CVE-2018-2628 is an easily exploitable vulnerability in the WLS Core Components of Oracle WebLogic Server affecting supported versions 10.3.6.0, 12.1.3.0, 12.2.1.2, and 12.2.1.3. The flaw is reachable by an unauthenticated attacker over the network via the T3 protocol and can be used to compromise the WebLogic Server instance. Public reporting characterizes successful exploitation as enabling takeover of the affected server. Specific vulnerable functions or code paths are not identified in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository contains two main Python scripts for exploiting Oracle WebLogic Server's CVE-2018-2628 deserialization vulnerability. The 'pocweblogic.py' script is a proof-of-concept that performs a T3 protocol handshake, sends a malicious serialized Java object, and checks for vulnerability by detecting a specific response pattern. It is used to verify if a target WebLogic server is vulnerable. The 'getshell.py' script is an interactive shell client that communicates with a deployed web shell (wlscmd.jsp) on the compromised server, allowing the attacker to execute arbitrary commands via HTTP requests. The repository is structured with a README (providing usage instructions and references), the two exploit scripts, and a .gitattributes file. The exploit requires network access to the target WebLogic server and leverages the T3 protocol (typically on port 7001). If successful, it can provide remote code execution and persistent access via a web shell.
This repository contains a single Metasploit module (modules/exploits/multi/misc/weblogic_deserialize.rb) that exploits a deserialization vulnerability (CVE-2018-2628) in Oracle WebLogic Server. The exploit targets the T3 protocol interface (default TCP port 7001) and allows unauthenticated remote code execution by sending a malicious serialized object. The module supports both Unix and Windows targets, delivering customizable payloads such as reverse shells or Meterpreter sessions. The module includes a check method to fingerprint the WebLogic server and determine if it is likely vulnerable. The exploit is weaponized, leveraging Metasploit's payload system for flexible post-exploitation. The only endpoints referenced are the T3 port (7001) and the WebLogic login page for version detection.
This repository provides a working exploit for Oracle WebLogic Server CVE-2018-2628, a critical Java deserialization vulnerability that allows remote code execution. The structure includes both Java and Python code. The main workflow is: 1. The attacker runs a Java-based JRMPListener (src/main/java/ysoserial/exploit/JRMPListener.java) on a server they control, which will deliver a malicious payload when contacted. 2. The attacker uses the Java code (src/main/java/ysoserial/GeneratePayload.java and related payload classes) to generate a serialized Java object payload, customized with the attacker's JRMPListener IP and port. 3. The Python script (wls-cve-2018-2628-poc.py) is used to send the crafted payload to the target WebLogic server's T3 service port (default 7001). The script handles the handshake and payload delivery. 4. If the target is vulnerable, the WebLogic server will deserialize the payload, connect back to the attacker's JRMPListener, and execute arbitrary commands specified by the attacker. The repository includes multiple payload generation methods (JRMPClient2, JRMPClient3) to bypass certain patches. The exploit is operational and can be used to achieve remote code execution on unpatched or improperly patched WebLogic servers. The code is modular, with clear separation between payload generation, listener setup, and exploit delivery. No hardcoded IPs or domains are present; the attacker supplies these at runtime. The README provides detailed usage instructions and context for the exploit.
This repository provides a working exploit for CVE-2018-2628, a critical deserialization vulnerability in Oracle WebLogic Server. The structure includes two main Python scripts: 'CVE-2018-2628-Getshell.py' (for exploitation and webshell upload) and 'CVE-2018-2628-poc.py' (for vulnerability detection and proof-of-concept). The 'wlscmd.jsp' file is a JSP webshell that is uploaded to the target server, enabling remote command execution via HTTP requests with base64-encoded commands. The 'cve-2018-2628.py' script is a client for interacting with the webshell, allowing the user to send commands and receive output. The exploit works by sending a crafted serialized payload over the T3 protocol to the target WebLogic server, exploiting the deserialization flaw to write the webshell to disk. The README provides usage instructions and example output. The repository is operational and provides a real, working exploit with a functional payload, targeting Oracle WebLogic servers vulnerable to CVE-2018-2628.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability mentioned only as a listed exploit possibly used by BlackTech; no further details are provided.
An Oracle WebLogic vulnerability exploited in the wild after an initial patch was found insufficient, enabling continued compromise (noted for cryptomining activity).
Remote code execution vulnerability in Oracle WebLogic referenced as a PoC capability the attacker prepared.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.