September 8, 2022 · Applied Cybernetics Group
CVE-2018-2628 — Oracle WebLogic Server
Oracle WebLogic Server Unspecified Vulnerability
- Added to KEV
2022-09-08- Federal due date
2022-09-29- Vendor
- Oracle
- Product
- WebLogic Server
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-2628
CISA short description
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Required action
Apply updates per vendor instructions.