KEVIntel
7.5
CVSS
High

CVE-2019-2725

PUBLISHED

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Oracle Corporation
Product
Tape Library ACSLS
Published
Apr 26, 2019
EPSS

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

cisa malware ransomware nuclei_scanner metasploit

CVSS scores

CVSS v3.0 7.5 High

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploitation status

Exploited in the wild

Recorded 2022-01-10 00:00:00 UTC · Source

Used in malware

Recorded 2022-01-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 10, 2022
CISA Jan 10, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

weblogic_deserialize_asyncresponseservice

metasploit · Created Unknown

Metasploit module for CVE-2019-2725

ianxtianxt/CVE-2019-2725

github · Created 2019-11-05 14:35:16 UTC · 3 stars

CVE-2019-2725

pimps/CVE-2019-2725

github · Created 2019-08-23 01:42:57 UTC · 47 stars

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

kerlingcode/CVE-2019-2725

github · Created 2019-06-16 06:17:09 UTC · 11 stars

CVE-2019-2725 bypass pocscan and exp

jiansiting/CVE-2019-2725

github · Created 2019-06-15 12:51:19 UTC · 36 stars

weblogic绕过和wls远程执行

welove88888/CVE-2019-2725

github · Created 2019-06-11 00:49:56 UTC · 2 stars

TopScrew/CVE-2019-2725

github · Created 2019-06-10 05:12:44 UTC · 190 stars

CVE-2019-2725命令回显+webshell上传+最新绕过

lufeirider/CVE-2019-2725

github · Created 2019-05-29 01:57:05 UTC · 438 stars

CVE-2019-2725 命令回显

leerina/CVE-2019-2725

github · Created 2019-05-05 08:34:20 UTC · 2 stars

davidmthomsen/CVE-2019-2725

github · Created 2019-05-02 21:09:36 UTC · 1 stars

tobechenghuai/CNTA-2019-0014xCVE-2019-2725

github · Created 2019-04-28 02:18:42 UTC · 11 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit