CVE-2018-2893 is a critical vulnerability in Oracle WebLogic Server (Oracle Fusion Middleware, WLS Core Components) affecting supported versions 10.3.6.0, 12.1.3.0, 12.2.1.2, and 12.2.1.3. The issue is remotely exploitable by an unauthenticated attacker with network access to the server via the Oracle T3 protocol (commonly exposed on port 7001). Successful exploitation enables compromise/takeover of the WebLogic Server, consistent with remote code execution capability, and is scored CVSS v3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit for Oracle WebLogic Server targeting CVE-2018-2893, a remote code execution vulnerability. The main file, 'weblogic.py', is a standalone exploit script that connects to a specified WebLogic server over TCP, crafts and sends a serialized Java payload exploiting the T3 protocol, and triggers a reverse shell connection back to the attacker's machine. The attacker must provide the target's host and port, as well as their own host and port for the reverse shell. The README provides usage instructions and references to similar exploits. The exploit is operational, providing a working reverse shell if the target is vulnerable. No detection or scanning functionality is present; the script is designed for direct exploitation. The repository also contains a README and a Draw.io diagram file, but only 'weblogic.py' contains exploit code.
This repository provides an operational exploit for CVE-2018-2893, a critical remote code execution vulnerability in Oracle WebLogic Server. The main exploit script, 'weblogic.py', is a Python script that connects to a specified WebLogic server over the T3 protocol (default port 7001) and sends a crafted serialized Java payload to exploit the vulnerability. The payload is typically a Java serialized object (such as a CommonsCollections gadget) that, when deserialized by the vulnerable server, results in arbitrary code execution—commonly a reverse shell. The script requires three arguments: the target host, port, and the path to the payload file. The README provides usage instructions, references, and notes about the need for an accessible RMI server for reverse shell functionality. The repository also includes a simple 'push.sh' script for git operations. No hardcoded IP addresses or domains are present except for the example T3 endpoint. The exploit is not part of a framework and is a standalone operational exploit targeting unpatched Oracle WebLogic servers.
This repository provides an exploit for CVE-2018-2893, a critical Java deserialization vulnerability in Oracle WebLogic Server. The exploit consists of a Python script (weblogic.py) and instructions in the README.md. The attack requires generating a malicious serialized Java object using ysoserial-cve-2018-2893.jar (not included in the repo), which is then delivered to the target WebLogic server over the T3 protocol (typically port 7001) using the Python script. The script crafts a custom T3 protocol header and sends the payload, potentially resulting in remote code execution on the server. The README provides step-by-step usage, including payload generation and exploit execution. The repository is operational and can be used to exploit vulnerable WebLogic instances, provided the attacker can connect to the target's T3 port and generate the appropriate payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Oracle WebLogic vulnerability enabling remote takeover of vulnerable servers without needing a password; exploitation increased after public PoC release.
A remote code execution vulnerability in Oracle WebLogic Server that was patched by Oracle on 2018-07-18 and then rapidly exploited by the tracked “luoxk” campaign to execute a Java-based payload downloader and deploy DDoS malware and XMRig cryptominer components.
A critical unauthenticated remote code execution vulnerability in Oracle WebLogic Server reachable over the Oracle T3 protocol, enabling full server compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.