vendor:
WebLogic Server
by:
Avinash Kumar Thapa
9.8
CVSS
CRITICAL
CVE-2019-2725
272
CWE
Product Name: WebLogic Server
Affected Version From: 10.3.6.0.0
Affected Version To: 12.1.3.0.0
Patch Exists: NO
Related CWE: CVE-2019-2725
CPE: a:oracle:weblogic_server
Tags: packetstorm,kev,edb,cve,cve2019,oracle,weblogic,rce
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei References:
https://paper.seebug.org/910/, https://www.exploit-db.com/exploits/46780/, https://www.oracle.com/security-alerts/cpujan2020.html, https://nvd.nist.gov/vuln/detail/CVE-2019-2725, http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
Nuclei Metadata: {'max-request': 2, 'vendor': 'oracle', 'product': 'agile_plm'}
Platforms Tested: Windows 2012 R2 (Build 9600), x64
2019
Oracle Weblogic Exploit CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
Mitigation:
Unknown