CVE-2018-2894 is a vulnerability found in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services).12.1.3.0, 12.2.1.2, and 12.2.1.3 are the supported versions that are affected. Oracle WebLogic Server is vulnerable to an easily exploited vulnerability that allows an unauthenticated attacker with network access through HTTP to compromise it. Oracle WebLogic Server may be taken over if this vulnerability is exploited successfully.
In order to patch this vulnerability, please install the official patch Oracle made available for supported, vulnerable instances.