CVE-2019-2725

KEV
Published: Apr 26, 2019 Last Modified: Ott 27, 2025
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
HIGH 7,5
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,9447
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Other Integrity Non-Repudiation
Potential Impacts:
Read Application Data Bypass Protection Mechanism Alter Execution Logic Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
Exploit

Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code …

Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution

View Exploit Code →
Exploit

Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code …

Verified Remote

Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)

View Exploit Code →
Application

Tape Library Acsls by Oracle

cpe:2.3:a:oracle:tape_library_acsls:8.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Vm Virtualbox by Oracle

Version Range Affected
To 5.2.36 (exclusive)
cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Vm Virtualbox by Oracle

Version Range Affected
From 6.0.0 (inclusive)
To 6.0.16 (exclusive)
cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Converged Application Server by Oracle

cpe:2.3:a:oracle:communications_converged_application_server:5.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Vm Virtualbox by Oracle

cpe:2.3:a:oracle:vm_virtualbox:5.2.36:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Converged Application Server by Oracle

cpe:2.3:a:oracle:communications_converged_application_server:7.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Vm Virtualbox by Oracle

Version Range Affected
From 6.1.0 (inclusive)
To 6.1.2 (exclusive)
cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Converged Application Server by Oracle

cpe:2.3:a:oracle:communications_converged_application_server:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Agile Plm by Oracle

cpe:2.3:a:oracle:agile_plm:9.3.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Agile Plm by Oracle

cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Storagetek Tape Analytics Sw Tool by Oracle

cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Agile Plm by Oracle

cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Tape Virtual Storage Manager Gui by Oracle

cpe:2.3:a:oracle:tape_virtual_storage_manager_gui:6.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019…
http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserializat…
https://support.f5.com/csp/article/K90059138
https://www.exploit-db.com/exploits/46780/
https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
https://www.oracle.com/security-alerts/cpujan2020.html
http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295…
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
http://www.securityfocus.com/bid/108074
http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserializat…
https://support.f5.com/csp/article/K90059138
https://www.exploit-db.com/exploits/46780/
https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
https://www.oracle.com/security-alerts/cpujan2020.html
http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295…
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
http://www.securityfocus.com/bid/108074