CVE-2019-2890

HIGH

Oracle WebLogic Server - RCE

Title source: llm

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Exploits (7)

nomisec WORKING POC 85 stars
by l1nk3rlin · poc
https://github.com/l1nk3rlin/CVE-2019-2890
nomisec WORKING POC 44 stars
by jas502n · poc
https://github.com/jas502n/CVE-2019-2890
nomisec WORKING POC 17 stars
by zhzhdoai · poc
https://github.com/zhzhdoai/Weblogic_Vuln
nomisec WORKING POC 11 stars
by ZO1RO · poc
https://github.com/ZO1RO/CVE-2019-2890
nomisec WORKING POC 4 stars
by ianxtianxt · poc
https://github.com/ianxtianxt/CVE-2019-2890
nomisec WORKING POC 1 stars
by Ky0-HVA · poc
https://github.com/Ky0-HVA/CVE-2019-2890
nomisec WORKING POC
by freeide · poc
https://github.com/freeide/weblogic_cve-2019-2890

Scores

CVSS v3 7.2
EPSS 0.9034
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
Published Oct 16, 2019
Tracked Since Feb 18, 2026