Select Page

[Overview]

WebLogic Server is a Java application server platform for developing, integrating, deploying, and managing large distributed Web applications and database applications. Recently, Oracle released an update patch to fix the WebLogic Server deserialization vulnerability.

[Vulnerability Details]

CVE-2018-2893: The vulnerability is caused by deserializing suspicious data in a T3 protocol request. An unauthorized attacker could exploit this vulnerability by sending a request for a specially crafted UnicastRef object to a vulnerable service. If the vulnerability is exploited successfully, the JRMP session output between the target server and the controlled server will allow the attacker to respond with malicious serialized objects that are not matched by the blacklist, causing Oracle WebLogic Server to be taken over.

Vulnerability Source: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2893

[Severity]

Critical

[Affected Versions]

  • Oracle WebLogic Server 10.3.6.0
  • Oracle WebLogic Server 12.1.3.0
  • Oracle WebLogic Server 12.2.1.2
  • Oracle WebLogic Server 12.2.1.3

[Suggestions]

Update the bug fix release provided by Oracle to eliminate the damage caused by the vulnerability.


Prevent WebLogic Server from communicating with suspicious network through port 7001.

Official statement: http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html

[Hillstone Networks Solution]

Hillstone Networks has added signatures to the IPS signature database version 2.1.249. By deploying any Hillstone Networks solution with the IPS function, the Oracle WebLogic Server Activator Insecure Deserialization vulnerability can be quickly detected and effectively intercepted, preventing the server from being attacked.

Threat Events Detected by Hillstone Solutions

Vulnerability Detail Description

Hillstone NGFWs Recognized for 8th Straight Year in Gartner® Magic Quadrant™, Named as a “Visionary”

Hillstone Networks Wins 2021 CybersecAsia Readers’ Choice Award

ZTNA: A Better Way to Control Access, Boost Security

Hillstone sBDS V3.4 Extends Supplementary Detection Capabilities

Kudos to the Hillstone Security Research Team for Being Acknowledge by Microsoft for Vulnerability Discovery

Hillstone Releases iSource, an Extended Detection and Response Platform

Hillstone’s A200W streamlines deployment of cost-effective perimeter solution

Endpoint Detection and Response: Getting from Good to Great

ADC V2.9 delivers traffic and balances links at an unprecedented level