CVE-2019-2890 is a vulnerability in Oracle WebLogic Server (versions 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0) within the Web Services component. The flaw allows a high-privileged attacker with network access via the T3 protocol to compromise the server. The vulnerability is easily exploitable and can lead to a full takeover of the affected WebLogic Server instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2019-2890, a deserialization vulnerability in Oracle WebLogic Server's T3 protocol. The main file, CVE-2019-2890.py, reads a list of target IP addresses and ports from 'url.txt', then attempts to connect to each target using a custom T3 handshake. It sends a crafted serialized Java object payload to test for the vulnerability. The script reports which targets are vulnerable, not vulnerable, or require further testing. The exploit is network-based and targets Oracle WebLogic servers with the T3 protocol enabled. The repository structure is simple, consisting of the exploit script and a README file. No hardcoded endpoints are present; all targets are supplied by the user via 'url.txt'.
This repository provides a working exploit for Oracle WebLogic Server CVE-2019-2890, a deserialization vulnerability that allows remote code execution via the T3 protocol. The exploit consists of Java source files for generating a malicious serialized object (poc.ser) and a Python script (weblogic.py) for delivering the payload to the target server. The Java code (Poc.java and PersistentContext.java) crafts a Registry proxy object pointing to an attacker-controlled JRMPListener (default 127.0.0.1:8000), which is then serialized and encrypted using WebLogic's encryption routines (requiring SerializedSystemIni.dat). The attacker runs ysoserial's JRMPListener to serve the actual command payload (e.g., calc.exe). The Python script connects to the target WebLogic server over TCP, sends the necessary T3 protocol headers, and delivers the serialized payload. The exploit requires access to certain WebLogic files and the ysoserial tool, and is operational with a working payload, but not fully weaponized (no automated payload customization).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.