# rabbitmask/WeblogicScan

Weblogic一键漏洞检测工具，V1.5，更新时间：20200730

Repository: https://github.com/rabbitmask/WeblogicScan
Canonical: https://ross.abutalabs.com/products/weblogicscan
Language: Python
License: MIT
License Family: permissive
Topics: weblogicscan
Last push: 2023-05-22T23:33:35+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2739, "days_push": 1199, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2261, forks 401 (observed 2026-08-28T04:06:31.785202+00:00)

## What it is
A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserialization, XMLDecoder deserialization, arbitrary file upload, console path disclosure) via POC detection. It supports single-target and batch scanning over the T3 protocol with version fingerprinting and logging.

## Use cases
- scan a WebLogic server for known CVEs
- detect WebLogic deserialization vulnerabilities
- batch scan a list of WebLogic targets
- identify WebLogic server version via T3 protocol
- check if WebLogic console or UDDI module is exposed
- test for SSRF CVE-2014-4210 on WebLogic

## When to choose
- you need a quick one-click check of WebLogic historical vulnerabilities
- you want batch scanning of multiple WebLogic targets with custom ports
- you need POC-only detection without exploit payloads for safe assessment

## When to avoid
- you need exploitation capabilities or recent 2020+ CVEs with full exploit chains
- you need a general-purpose web vulnerability scanner beyond WebLogic
- you require actively maintained tooling with frequent CVE updates

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: penetration-testing, vulnerability-scanning, security
- domain: security, penetration-testing, developer-tools
- platform: python, cli, windows
- tags: weblogic, poc-scanner, deserialization, cve-detection, t3-protocol, batch-scanning, linux, macos

## Member repositories
- rabbitmask/WeblogicScan (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:31.785202+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:42:34.060178+00:00, confidence not recorded.
  - readme: https://github.com/rabbitmask/WeblogicScan (fetched 2026-08-28T04:06:31.785202+00:00, sha 100bc1aa508a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
