CVE-2019-2725

CRITICAL KEV RANSOMWARE NUCLEI

Oracle Agile Plm < 5.2.36 - Injection

Title source: rule

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (27)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/46814
exploitdb WORKING POC
by Avinash Kumar Thapa · pythonwebappswindows
https://www.exploit-db.com/exploits/46780
nomisec WORKING POC 506 stars
by shack2 · poc
https://github.com/shack2/javaserializetools
nomisec WORKING POC 436 stars
by lufeirider · remote
https://github.com/lufeirider/CVE-2019-2725
nomisec WORKING POC 105 stars
by SkyBlueEternal · poc
https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961
nomisec WORKING POC 69 stars
by black-mirror · remote
https://github.com/black-mirror/Weblogic
nomisec WORKING POC 51 stars
by pimps · remote
https://github.com/pimps/CVE-2019-2725
nomisec STUB 36 stars
by jiansiting · poc
https://github.com/jiansiting/CVE-2019-2725
nomisec WORKING POC 21 stars
by lasensio · poc
https://github.com/lasensio/cve-2019-2725
nomisec WORKING POC 11 stars
by kerlingcode · remote
https://github.com/kerlingcode/CVE-2019-2725
nomisec WORKING POC 11 stars
by tobechenghuai · poc
https://github.com/tobechenghuai/CNTA-2019-0014xCVE-2019-2725
nomisec WORKING POC 7 stars
by zhusx110 · poc
https://github.com/zhusx110/cve-2019-2725
nomisec NO CODE 3 stars
by ianxtianxt · remote
https://github.com/ianxtianxt/CVE-2019-2725
nomisec WORKING POC 2 stars
by GGyao · remote
https://github.com/GGyao/weblogic_2019_2725_wls_batch
nomisec WORKING POC 2 stars
by welove88888 · poc
https://github.com/welove88888/CVE-2019-2725
nomisec WORKING POC 2 stars
by leerina · poc
https://github.com/leerina/CVE-2019-2725
nomisec SCANNER 1 stars
by ludy-dev · remote
https://github.com/ludy-dev/Oracle-WLS-Weblogic-RCE
nomisec WORKING POC 1 stars
by davidmthomsen · poc
https://github.com/davidmthomsen/CVE-2019-2725
nomisec WORKING POC
by loursha · remote-auth
https://github.com/loursha/Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725
nomisec WORKING POC
by CalegariMindSec · remote
https://github.com/CalegariMindSec/Exploit-CVE-2019-2725
nomisec SUSPICIOUS
by N0b1e6 · remote
https://github.com/N0b1e6/CVE-2019-2725-POC
vulncheck_xdb SCANNER
remote
https://github.com/Donghan-gugugu/weblogic-CVE2019-POC
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_asyncresponseservice.rb

Nuclei Templates (1)

Oracle WebLogic Server - Remote Command Execution
CRITICALby dwisiswant0

Scores

CVSS v3 9.8
EPSS 0.9447
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-01-10
VulnCheck KEV 2019-04-30
InTheWild.io 2020-03-17
ENISA EUVD EUVD-2019-12364
Ransomware Use Confirmed
CWE
CWE-74
Status published
Products (16)
oracle/agile_plm 9.3.3
oracle/agile_plm 9.3.4
oracle/agile_plm 9.3.5
oracle/communications_converged_application_server 5.1
oracle/communications_converged_application_server 7.0
oracle/communications_converged_application_server 7.1
oracle/peoplesoft_enterprise_peopletools 8.56
oracle/peoplesoft_enterprise_peopletools 8.57
oracle/peoplesoft_enterprise_peopletools 8.58
oracle/storagetek_tape_analytics_sw_tool 2.3
... and 6 more
Published Apr 26, 2019
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026