CVE-2019-2725

CRITICAL KEV RANSOMWARE NUCLEI

Oracle WebLogic Server 10.3.6.0.0 and 12.1.3.0.0 - Unauthenticated Remote Code Execution via HTTP

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-2725 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 10, 2022, with confirmed use in ransomware campaigns. EIP tracks 25 public exploits from researchers including Metasploit, Avinash Kumar Thapa, shack2, including a Metasploit module exploits/multi/misc/weblogic_deserialize_asyncresponseservice. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits CVE-2019-2725, an unauthenticated deserialization vulnerability in Oracle WebLogic Server's AsyncResponseService. It sends a malicious SOAP request to execute arbitrary commands via Java deserialization.

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (25)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/46814

This Metasploit module exploits CVE-2019-2725, an unauthenticated deserialization vulnerability in Oracle WebLogic Server's AsyncResponseService. It sends a malicious SOAP request to execute arbitrary commands via Java deserialization.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the Oracle WebLogic Server T3 interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by Avinash Kumar Thapa · pythonwebappswindows
https://www.exploit-db.com/exploits/46780

This exploit targets CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server, allowing unauthenticated RCE via HTTP. The PoC uses a crafted payload to execute a reverse shell via PowerShell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0
No auth needed
Prerequisites: Network access to the target WebLogic Server · PowerShell available on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 506 stars
by shack2 · poc
https://github.com/shack2/javaserializetools

This repository contains a functional exploit tool for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The tool includes multiple payloads for different versions of WebLogic and provides a GUI for executing checks and exploits.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions 10.x and 12.x)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Vulnerable version of WebLogic Server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 436 stars
by lufeirider · remote
https://github.com/lufeirider/CVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit leverages Java deserialization gadgets (TemplatesImpl) to achieve remote code execution (RCE) by crafting malicious serialized data.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions affected by CVE-2019-2725)
No auth needed
Prerequisites: Network access to vulnerable WebLogic Server · Java runtime environment
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 105 stars
by SkyBlueEternal · poc
https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

This repository contains a functional Python script that exploits CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The PoC sends a malicious SOAP request to trigger remote code execution via the AsyncResponseService endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.x, 12.1.3
No auth needed
Prerequisites: Network access to the WebLogic Server · SOAP endpoint exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 69 stars
by black-mirror · remote
https://github.com/black-mirror/Weblogic

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit uploads a webshell and executes commands, demonstrating remote code execution (RCE) capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions 10.3.6 and 12.1.3)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Vulnerable WebLogic Server version
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 51 stars
by pimps · remote
https://github.com/pimps/CVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit supports multiple payloads and endpoints, demonstrating remote code execution (RCE) capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (multiple versions)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Python environment with required dependencies
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec STUB 36 stars
by jiansiting · poc
https://github.com/jiansiting/CVE-2019-2725

The repository contains only a minimal README with no exploit code or technical details. It references CVE-2019-2725 but provides no functional PoC or analysis.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Oracle WebLogic Server
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 21 stars
by lasensio · poc
https://github.com/lasensio/cve-2019-2725

This repository contains a functional Python exploit for CVE-2019-2725, an unauthenticated remote code execution vulnerability in Oracle WebLogic Server. The exploit sends a crafted SOAP request to trigger deserialization of malicious payloads, leading to arbitrary command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Target server must be vulnerable (unpatched)
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 11 stars
by kerlingcode · remote
https://github.com/kerlingcode/CVE-2019-2725

This repository contains functional exploit code for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit sends a crafted SOAP request to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the WebLogic Server · WebLogic Server with vulnerable wls-wsat component
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 11 stars
by tobechenghuai · poc
https://github.com/tobechenghuai/CNTA-2019-0014xCVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit uses ysoserial to generate a malicious payload and crafts a SOAP request to trigger remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Access to ysoserial tool · Network access to vulnerable WebLogic Server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 7 stars
by zhusx110 · poc
https://github.com/zhusx110/cve-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit sends a crafted SOAP request to execute arbitrary commands via ProcessBuilder, demonstrating remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions affected by CVE-2019-2725)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Target server must be vulnerable to CVE-2019-2725
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec NO CODE 3 stars
by ianxtianxt · remote
https://github.com/ianxtianxt/CVE-2019-2725
nomisec WORKING POC 2 stars
by GGyao · remote
https://github.com/GGyao/weblogic_2019_2725_wls_batch

This repository contains a functional exploit for CVE-2019-2725, targeting the Oracle WebLogic Server wls-wsat component. The exploit leverages deserialization to achieve remote code execution (RCE) by sending crafted SOAP requests with malicious payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (wls-wsat component)
No auth needed
Prerequisites: Network access to the vulnerable WebLogic Server · Target server must have the wls-wsat component exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by welove88888 · poc
https://github.com/welove88888/CVE-2019-2725

This repository contains a functional Python exploit for CVE-2019-2725, targeting Oracle WebLogic Server versions 10.3.6 and 12.1.3. The exploit leverages deserialization vulnerabilities to achieve remote command execution (RCE) and webshell upload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server 10.3.6, 12.1.3
No auth needed
Prerequisites: Network access to vulnerable WebLogic Server · Python 3 environment with requests and logzero libraries
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 2 stars
by leerina · poc
https://github.com/leerina/CVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit sends a crafted SOAP request with a malicious payload to achieve remote code execution (RCE) via a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Target WebLogic Server with vulnerable endpoint exposed · Network access to the target · Listener set up for reverse shell
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SCANNER 1 stars
by ludy-dev · remote
https://github.com/ludy-dev/Oracle-WLS-Weblogic-RCE

The repository contains a Python script that checks for the presence of vulnerable endpoints in Oracle WebLogic Server (CVE-2019-2725) by sending HTTP requests and analyzing responses. It does not include exploit code for achieving RCE but confirms vulnerability presence.

Classification
Scanner 90%
Attack Type
Deserialization
Complexity
Trivial
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the target WebLogic Server · Vulnerable endpoints exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by davidmthomsen · poc
https://github.com/davidmthomsen/CVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit crafts a malicious SOAP request to execute arbitrary commands on the target system via ProcessBuilder.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: Network access to the WebLogic Server · WebLogic Server with vulnerable endpoint exposed
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by loursha · remote-auth
https://github.com/loursha/Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725

This repository contains a functional Python exploit for CVE-2019-2725, a critical deserialization vulnerability in Oracle WebLogic Server's AsyncResponseService. The exploit sends a malicious SOAP request to execute arbitrary commands, demonstrated via a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (10.3.6.0.0, 12.1.3.0.0, and others prior to April 2019 CPU)
No auth needed
Prerequisites: Network access to the vulnerable WebLogic Server endpoint · Exposed /_async/AsyncResponseService endpoint
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by CalegariMindSec · remote
https://github.com/CalegariMindSec/Exploit-CVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit leverages a crafted SOAP request to execute arbitrary commands via Java deserialization, resulting in remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions affected by CVE-2019-2725)
No auth needed
Prerequisites: Network access to the target WebLogic Server · Target server must be vulnerable to CVE-2019-2725
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec SUSPICIOUS
by N0b1e6 · remote
https://github.com/N0b1e6/CVE-2019-2725-POC

The repository lacks actual exploit code and instead instructs users to modify a 'txt' file with a '大马地址' (likely a malicious payload URL) and use Burp Suite to send a POST request. No technical details about CVE-2019-2725 are provided.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Oracle WebLogic Server (unspecified version)
No auth needed
Prerequisites: Burp Suite · access to modify and send crafted POST requests
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by peterpeter228 · poc
https://github.com/peterpeter228/CNTA-2019-0014xCVE-2019-2725

This repository contains a functional exploit for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. The exploit uses ysoserial to generate a malicious payload and crafts a SOAP request to trigger remote code execution.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: ysoserial tool · network access to target WebLogic Server
devstral-2 · analyzed May 20, 2026 Full analysis →
vulncheck_xdb SCANNER
remote
https://github.com/Donghan-gugugu/weblogic-CVE2019-POC

This repository contains a scanner for CVE-2019-2725, a deserialization vulnerability in Oracle WebLogic Server. It includes a script to collect potential targets from a search engine and another script to check for the presence of the vulnerability by sending a request to a specific endpoint.

Classification
Scanner 90%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: access to a search engine API (FOFA) · list of target URLs
devstral-2 · analyzed Feb 25, 2026 Full analysis →
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner

This repository contains a Python-based scanner for detecting multiple WebLogic vulnerabilities, including CVE-2019-2725. It checks for the presence of vulnerable modules but does not include functional exploit code for achieving RCE or other offensive actions.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server
No auth needed
Prerequisites: network access to target WebLogic server
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_asyncresponseservice.rb

This Metasploit module exploits a deserialization vulnerability in Oracle WebLogic Server's AsyncResponseService via a malicious SOAP request, leading to remote code execution. It supports multiple platforms (Unix, Windows, Solaris) and delivers payloads tailored to each target.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (versions affected by CVE-2019-2725)
No auth needed
Prerequisites: Network access to the Oracle WebLogic Server T3 interface · Vulnerable version of Oracle WebLogic Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Oracle WebLogic Server - Remote Command Execution
CRITICALby dwisiswant0

References (9)

Core 9
Core References
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108074
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K90059138
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/46780/
Patch, Vendor Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2020.html

Scores

CVSS v3 9.8
EPSS 0.9447
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2022-01-10
VulnCheck KEV 2019-04-30
InTheWild.io 2020-03-17
ENISA EUVD EUVD-2019-12364
Ransomware Use Confirmed
CWE
CWE-74
Status published
Products (16)
oracle/agile_plm 9.3.3
oracle/agile_plm 9.3.4
oracle/agile_plm 9.3.5
oracle/communications_converged_application_server 5.1
oracle/communications_converged_application_server 7.0
oracle/communications_converged_application_server 7.1
oracle/peoplesoft_enterprise_peopletools 8.56
oracle/peoplesoft_enterprise_peopletools 8.57
oracle/peoplesoft_enterprise_peopletools 8.58
oracle/storagetek_tape_analytics_sw_tool 2.3
... and 6 more
Published Apr 26, 2019
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026