CVE-2018-2894 is a critical vulnerability affecting Oracle WebLogic Server versions 12.1.3.0, 12.2.1.2, and 12.2.1.3, specifically within the WLS - Web Services subcomponent. This easily exploitable flaw allows an unauthenticated attacker to compromise the server via HTTP, leading to complete takeover with full confidentiality, integrity, and availability impacts. With a CVSS v3.0 score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk. While not listed in CISA KEV, Nuclei templates for Remote Code Execution exist, and it has garnered substantial community discussion and media coverage, including mentions in articles about ransomware and backdoors leveraging exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.3.6.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:* | ||
12.1.3.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:* | ||
12.2.1.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.2.0:*:*:*:*:*:*:* | ||
12.2.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:weblogic_server:12.2.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.