V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-2725
CVE
Critical KEVConfirmedExploit available

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are…

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2019-01-01
Updated
2022-01-10
Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Tags · CWE
KEVPre-auth
CWE-74
CAPEC-3
CAPEC-6
CAPEC-7
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-13
CAPEC-14
CAPEC-24
CAPEC-28
CAPEC-34
CAPEC-42
CAPEC-43
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-51
CAPEC-52
CAPEC-53
CAPEC-64
CAPEC-67
CAPEC-71
CAPEC-72
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-80
CAPEC-83
CAPEC-84
CAPEC-101
CAPEC-105
CAPEC-108
CAPEC-120
CAPEC-135
CAPEC-250
CAPEC-267
CAPEC-273
Affected products
Agile_plmCommunications_converged_application_serverPeoplesoft_enterprise_peopletoolsStoragetek_tape_analytics_sw_toolTape_library_acslsTape_virtual_storage_manager_guiVm_virtualbox < 5.2.36Vm_virtualbox 6.0.0–6.0.16Vm_virtualbox 6.1.0–6.1.2Vm_virtualboxWeblogic_server
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2022-01-10
Added to KEV
2022-01-10
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.945 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
CVE-2019-2725
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
46780
exploitdb · https://www.exploit-db.com/exploits/46780
Enterprise
46814
exploitdb · https://www.exploit-db.com/exploits/46814
Enterprise
Affected software
ProductVendorStatus
agile_plm*Exploited
communications_converged_application_server*Exploited
peoplesoft_enterprise_peopletools*Exploited
storagetek_tape_analytics_sw_tool*Exploited
tape_library_acsls*Exploited
tape_virtual_storage_manager_gui*Exploited
vm_virtualbox*Exploited
weblogic_server*Exploited
Source databases
CVE
Related vulnerabilities