SOURCE FACT
Oracle · WebLogic Server
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Required action
Apply updates per vendor instructions.
CISA notes
https://www.oracle.com/security-alerts/cpuapr2018.html; https://nvd.nist.gov/vuln/detail/CVE-2018-2628
View source evidence →