Looking for the vulnerability index of Invicti's legacy products?
Oracle Weblogic T3 XXE (CVE-2019-2888) - Vulnerability Database

Oracle Weblogic T3 XXE (CVE-2019-2888)

Description

T3 is a special RMI protocol implemented in Weblogic. It's vulnerable to an XML extenal entity injection. An attacker can send crafted requests to a web application for extraction of secrets from the file system, server-side request forgery or denial-of-service attacks.

Remediation

Upgrade to the latest version of Oracle WebLogic Server. This issue was fixed in Oracle Critical Patch Update - April 2019. Or disable/restrict access to T3

Related Vulnerabilities