Junglewise Threat Intelligence

CVE-2019-2725: Oracle WebLogic Server, Injection

CVE-2019-2725 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-10

Technologies: Oracle Agile PLM, Oracle WebLogic Server, Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

An injection vulnerability in the Web Services subcomponent of Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server. Successful exploitation can lead to a complete takeover of the affected Oracle WebLogic Server instance.

Affected products

  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0
  • Oracle Agile PLM 9.3.3, 9.3.4, 9.3.5
  • Oracle Communications Converged Application Server 5.1, 7.0, 7.1
  • Oracle PeopleSoft Enterprise PeopleTools 8.56, 8.57, 8.58

Timeline

  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats