Vulnerability record · CVE-2018-2628 · published 19 April 2018
CVE-2018-2628: Oracle WebLogic Server T3 deserialization allows unauthenticated remote takeover
Oracle · Weblogic Server
Oracle WebLogic Server contains a deserialization of untrusted data flaw (CWE-502) in the WLS Core Components, reachable over the T3 protocol. An unauthenticated network attacker can send crafted serialized data to the T3 listener and achieve remote code execution, leading to full takeover of the server. The affected supported versions are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.
Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network RCE, CISA KEV listing, public exploits and near-maximum EPSS make this an urgent patch-or-mitigate item.
What it is
Oracle WebLogic Server contains a deserialization of untrusted data flaw (CWE-502) in the WLS Core Components, reachable over the T3 protocol. An unauthenticated network attacker can send crafted serialized data to the T3 listener and achieve remote code execution, leading to full takeover of the server. The affected supported versions are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3.
Impact
Successful exploitation gives the attacker complete control of the WebLogic Server process, with high confidentiality, integrity and availability impact. This typically means arbitrary code execution in the server's context and potential lateral movement into connected systems.
Attack surface
The flaw is reached over the network via the T3 protocol, which is exposed by default on WebLogic Server. No authentication or user interaction is required, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-09-08, and public Exploit-DB entries exist, indicating active exploitation. EPSS is 0.99448 (99.9th percentile), consistent with very high likelihood of exploitation.
What to do
- Apply the Oracle April 2018 CPU patch for the affected WebLogic versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3) as the primary fix.
- Restrict network access to the T3/T3S listener so only trusted hosts can reach it; block T3 from untrusted networks.
- If T3 is not required, disable the T3 protocol or filter it at the network layer.
- Run WebLogic with least privilege and isolate it from sensitive internal networks to limit post-exploitation movement.
- Monitor for and apply any later Oracle CPU updates that supersede the April 2018 fix.
Detection
- Monitor network traffic to WebLogic T3 ports for anomalous serialized payloads or unexpected T3 handshakes from untrusted sources.
- Alert on WebLogic server process spawning child processes such as cmd.exe, /bin/sh, or other unexpected executables.
- Review WebLogic logs for T3 connection errors, deserialization exceptions, or unusual class loading activity.
- Hunt for outbound connections from WebLogic hosts to unknown external IPs following T3 traffic, which may indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-2628 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "Oracle WebLogic Server Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-2628 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-2628), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.