CVE-2019-2725
CRITICAL KEV RANSOMWARE NUCLEIOracle Agile Plm < 5.2.36 - Injection
Title source: ruleDescription
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploits (27)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/46814
exploitdb
WORKING POC
by Avinash Kumar Thapa · pythonwebappswindows
https://www.exploit-db.com/exploits/46780
nomisec
WORKING POC
105 stars
by SkyBlueEternal · poc
https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961
nomisec
WORKING POC
11 stars
by tobechenghuai · poc
https://github.com/tobechenghuai/CNTA-2019-0014xCVE-2019-2725
gitlab
by DeserializeExploit · poc
https://gitlab.com/penetration-test-learn/10vuln/DeserializeExploit/javaserializetools
nomisec
WORKING POC
by loursha · remote-auth
https://github.com/loursha/Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725
nomisec
WORKING POC
by CalegariMindSec · remote
https://github.com/CalegariMindSec/Exploit-CVE-2019-2725
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_asyncresponseservice.rb
Nuclei Templates (1)
Oracle WebLogic Server - Remote Command Execution
CRITICALby dwisiswant0
Scores
CVSS v3
9.8
EPSS
0.9447
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-01-10
VulnCheck KEV
2019-04-30
InTheWild.io
2020-03-17
ENISA EUVD
EUVD-2019-12364
Ransomware Use
Confirmed
CWE
CWE-74
Status
published
Products (16)
oracle/agile_plm
9.3.3
oracle/agile_plm
9.3.4
oracle/agile_plm
9.3.5
oracle/communications_converged_application_server
5.1
oracle/communications_converged_application_server
7.0
oracle/communications_converged_application_server
7.1
oracle/peoplesoft_enterprise_peopletools
8.56
oracle/peoplesoft_enterprise_peopletools
8.57
oracle/peoplesoft_enterprise_peopletools
8.58
oracle/storagetek_tape_analytics_sw_tool
2.3
... and 6 more
Published
Apr 26, 2019
KEV Added
Jan 10, 2022
Tracked Since
Feb 18, 2026