cbcvebase.
CVE-2019-2725
published 2019-04-26

CVE-2019-2725: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-10
Exploited in the wild
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

19 ranges
VendorProductVersion rangeFixed in
oracleagile_plm
oracleagile_plm
oracleagile_plm
oraclecommunications_converged_application_server
oraclecommunications_converged_application_server
oraclecommunications_converged_application_server
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclestoragetek_tape_analytics_sw_tool
oracletape_library_acsls
oracletape_virtual_storage_manager_gui
oraclevm_virtualbox< 5.2.365.2.36
oraclevm_virtualbox
oraclevm_virtualbox>= 6.0.0 < 6.0.166.0.16
oraclevm_virtualbox>= 6.1.0 < 6.1.26.1.2
oracleweblogic_server
oracleweblogic_server
oracle_corporationtape_library_acsls

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL