Vulnerability record · CVE-2018-3191 · published 17 October 2018
CVE-2018-3191: Oracle WebLogic Server T3 deserialization flaw allows unauthenticated takeover
Oracle · Weblogic Server
CVE-2018-3191 is a vulnerability in the WLS Core Components subcomponent of Oracle WebLogic Server affecting versions 10.3.6.0, 12.1.3.0 and 12.2.1.3. It is easily exploitable by an unauthenticated attacker with network access via T3 and can result in full takeover of the server. The record does not specify the underlying weakness beyond 'insufficient information', so the exact root cause is not stated here.
Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a very high EPSS percentile, makes this a top-priority patch for exposed WebLogic instances.
What it is
CVE-2018-3191 is a vulnerability in the WLS Core Components subcomponent of Oracle WebLogic Server affecting versions 10.3.6.0, 12.1.3.0 and 12.2.1.3. It is easily exploitable by an unauthenticated attacker with network access via T3 and can result in full takeover of the server. The record does not specify the underlying weakness beyond 'insufficient information', so the exact root cause is not stated here.
Impact
An unauthenticated remote attacker can fully compromise the WebLogic Server, affecting confidentiality, integrity and availability, effectively gaining control of the host and any data or services it exposes.
Attack surface
Reachable over the network through the T3 protocol; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any WebLogic instance exposing T3 to untrusted networks is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.63188, 99.168th percentile), indicating strong likelihood of exploitation activity. References are patch and advisory entries only; no public exploit tag is present in the record.
What to do
- Apply the Oracle October 2018 CPU patch for WebLogic Server (versions 10.3.6.0, 12.1.3.0, 12.2.1.3) as the primary fix.
- Restrict network access to the T3 listener so only trusted hosts can reach it; block T3 from untrusted networks.
- Where T3 is not required, disable or filter the T3 protocol at the network and WebLogic configuration level.
- Monitor and audit WebLogic instances for unexpected outbound connections or process behavior after exposure.
- If patching is delayed, isolate affected WebLogic servers behind strict network segmentation.
Detection
- Monitor T3 traffic to WebLogic servers for anomalous or unexpected connections from untrusted sources.
- Alert on unusual child processes or command execution spawned by the WebLogic Java process.
- Review WebLogic logs for unexpected deserialization errors, class loading anomalies or T3 handshake irregularities.
- Track outbound network connections from WebLogic hosts to unknown destinations as a possible post-exploitation indicator.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/105613 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041896 | Third Party AdvisoryVDB Entry |
| http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/105613 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041896 | Third Party AdvisoryVDB Entry |
Track CVE-2018-3191 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3191), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.