CVE-2019-2729
published 2019-06-19CVE-2019-2729: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
88.83%
99.8th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_diameter_signaling_router | — | — |
| oracle | communications_network_integrity | 7.3.2 – 7.3.6 | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | rapid_planning | — | — |
| oracle | rapid_planning | — | — |
| oracle | storagetek_tape_analytics_sw_tool | — | — |
| oracle | tape_library_acsls | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP SOAP requests to /_async/* and /wls-wsat/* URL paths for malicious XML-serialized Java objects (XMLDecoder payloads) — these are the two endpoints that accept WorkContext deserialization input exploited by CVE-2019-2729. ↗
- →Trend Micro Deep Packet Inspection rule 1009816 covers exploitation of CVE-2019-2729 on Oracle WebLogic Server. ↗
- →Trend Micro Deep Discovery Inspector DDI rule 2903 detects possible Oracle WebLogic remote command execution exploit over HTTP. ↗
- →CVE-2019-2729 bypasses the CVE-2019-2725 blacklist by substituting the blacklisted XML tag with a <class> tag — look for SOAP/XMLDecoder payloads containing <class> tags in requests to WebLogic async/wsat endpoints. ↗
- →The exploit leverages UnitOfWorkChangeSet deserialization of an attacker-controlled byte array; detect SOAP requests containing UnitOfWorkChangeSet class references in XMLDecoder payloads. ↗
- ·Exploitation requires JDK 1.6; WebLogic 10.3.6 ships with JDK 1.6 by default, making it the primary at-risk version for this specific bypass technique. ↗
- ·Deleting _async.war and wls-wsat.war and restarting the WebLogic service prevents access to the vulnerable URLs as a temporary mitigation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Oracle WebLogic Server) — CVE-2019-2729
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Oracle WebLogic Server) — CVE-2019-2729
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Oracle WebLogic Server) vulnerability
CVE: CVE-2019-2729
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Integration (Oracle WebLogic Server) — CVE-2019-2729
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Integration (Oracle WebLogic Server) — CVE-2019-2729
Oracle Oracle Communications Applications Risk Matrix: Integration (Oracle WebLogic Server) vulnerability
CVE: CVE-2019-2729
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Oracle WebLogic Server) — CVE-2019-2729
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Oracle WebLogic Server) — CVE-2019-2729
Oracle Oracle Communications Applications Risk Matrix: IDIH Visualization (Oracle WebLogic Server) vulnerability
CVE: CVE-2019-2729
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Security (Oracle WebLogic Server) — CVE-2019-2729
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: Security (Oracle WebLogic Server) — CVE-2019-2729
Oracle Oracle PeopleSoft Risk Matrix: Security (Oracle WebLogic Server) vulnerability
CVE: CVE-2019-2729
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
GHSA
GHSA-hmxx-vvw4-43vc: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)
ghsa_unreviewed·2022-05-24
CVE-2019-2729 [CRITICAL] CWE-284 GHSA-hmxx-vvw4-43vc: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle communications_diameter_signaling_router Improper Access Control
vulncheck·2019·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle communications_diameter_signaling_router Improper Access Control
Oracle communications_diameter_signaling_router Improper Access Control
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected: Oracle communications_diameter_signaling_router
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if
No detection rules found.
Exploit-DB
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
exploitdb·2020-01-09·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
---
# Exploit Title: Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
# Date: 2020-01-08
# Exploit Author: Waffles & Paveway3
# Vendor Homepage: https://www.oracle.com/middleware/technologies/weblogic.html
# Version: 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0
# Tested on: Windows
# CVE : CVE-2019-2729
SerialLogic.py
# Exploit Title: SerialLogic
# Date: 01-08-2020
# Exploit Author: Waffles & Paveway3
# Vendor Homepage: https://www.oracle.com/middleware/technologies/weblogic.html
# Version: 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0
# Tested on: Windows
# CVE : CVE-2019-2729
import argparse
import requests
import sys
import os
import base64
# Colors for terminal output because I likes pretty things
class bcolors:
OKGREEN = '\033[92m'
BOLD = '\
Nuclei
Oracle WebLogic Server Administration Console - Remote Code Execution
nuclei·CVSS 9.8
CVE-2019-2729 [CRITICAL] Oracle WebLogic Server Administration Console - Remote Code Execution
Oracle WebLogic Server Administration Console - Remote Code Execution
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 0.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server.
Template:
id: CVE-2019-2729
info:
name: Oracle WebLogic Server Administration Console - Remote Code Execution
author: igibanez
severity: critical
description: |
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 0.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle WebL
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
CVE-2017-5638 [CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Threat Research Center
Trend Reports
Vulnerabilities
## Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Unit 42
Published: July 21, 2022
Trend Reports
Vulnerabilities
Apache Log4j
CVE-2017-5638
CVE-2017-9841
CVE-2018-19986
CVE-2019-02320
CVE-2019-19597
CVE-2019-9082
CVE-2020-14882
CVE-2020-14883
CVE-2020-15505
CVE-2020-15506
CVE-2020-25078
CVE-2020-5902
CVE-2021-21315
CVE-2021-22986
CVE-2021-26855
CVE-2021-31805
CVE-2021-34473
CVE-2021-35464
CVE-2021-38647
CVE-2021-40438
CVE-2021-40539
CVE-2021-41773
CVE-2021-42013
CVE-2021-44228
CVE-2021-45046
CVE-2022-22963
CVE-2022-22965
Network security trends
Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are repo
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
[CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are reported every year, but not all are used by threat actors in real-world attacks. There are many reasons for this: a proof of concept (PoC) may not be available for attackers to weaponize, it may be too difficult to exploit the vulnerability, there may be a lack of accessible vulnerable software on the internet, or attackers may simply deem a vulnerability not worth exploiting due to low impact. Real-world defenders need real-world data on which vulnerabilities attackers are choosing to exploit – and where to focus protections.
In the 2022 Unit 42 Network Threat Trends Research Report, we’ve used data captured by the Palo Alto Networks Advanced Threat Prevention security service on Next-Generation Firewall and Prisma SASE from
Tenable
Oracle July 2021 Critical Patch Update Addresses 231 CVEs
blogs_tenable·2021-07-21
Oracle July 2021 Critical Patch Update Addresses 231 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
blogs_tenable·2019-12-16
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution Q3 2019
blogs_securelist·2019-11-29
IT threat evolution Q3 2019
Table of Contents
Targeted attacks and malware campaigns
Mobile espionage targeting the Middle East
APT33 beefs up its toolset
New FinSpy iOS and Android implants found in the wild
Turla revamps its toolset
CloudAtlas uses new infection chain
Dtrack banking malware discovered
Other security news
Sodin ransomware attacks MSP
The impact of web mining
Mac OS threat landscape
Smart home vulnerabilities
Security of smart buildings
Smart cars and connected devices
Personal data theft
Authors
David Emm
## Targeted attacks and malware campaigns
## Mobile espionage targeting the Middle East
At the end of June we reported the details of a highly targeted campaign that we dubbed ‘Operation ViceLeaker’ involving the spread of malicious Android samples via instant messaging. The cam
Securelist
IT threat evolution Q3 2019
blogs_securelist·2019-11-29
IT threat evolution Q3 2019
Table of Contents
- Targeted attacks and malware campaigns
- Other security news
Authors
- David Emm
## Targeted attacks and malware campaigns
### Mobile espionage targeting the Middle East
At the end of June we reported the details of a highly targeted campaign that we dubbed ‘Operation ViceLeaker’ involving the spread of malicious Android samples via instant messaging. The campaign affected several dozen victims in Israel and Iran. We discovered this activity in May 2018, right after Israeli security agencies announced that Hamas had installed spyware on the smartphones of Israeli soldiers, and we released a private report on our Threat Intelligence Portal. We believe the malware has been in development since late 2016, but the main distribution began at the end of 2017. The attack
Tenable
Oracle Critical Patch Update for July Contains 265 Fixes
blogs_tenable·2019-07-16
Oracle Critical Patch Update for July Contains 265 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Exploits y vulnerabilidades
## Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran Jun 25, 2019 Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729 , in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is rela
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Exploits & Vulnerabilities
## Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran Jun 25, 2019 Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729 , in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is relat
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Exploits & Vulnerabilities
# Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran
2019/06/25
Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729, in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is relative
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Ausnutzung von Schwachstellen
## Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran Jun 25, 2019 Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729 , in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is re
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Exploits & Vulnerabilities
## Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran 2019/06/25 Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729 , in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is relativ
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Sfruttamento vulnerabilità
## Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran Jun 25, 2019 Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729 , in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is relat
Trendmicro
Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
blogs_trendmicro·2019-06-25·CVSS 7.4
CVE-2019-2729 [HIGH] Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Exploits & Vulnerabilities
# Remediating an RCE (CVE-2019-2729) in Oracle WebLogic
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability in an out-of-band security patch.
By: Sivathmican Sivakumaran
Jun 25, 2019
Read time: ( words)
Save to Folio
Oracle WebLogic has recently disclosed and patched remote-code-execution (RCE) vulnerabilities in its software, many of which were due to insecure deserialization. Oracle addressed the most recent vulnerability, CVE-2019-2729, in an out-of-band security patch on June 18, 2019.
CVE-2019-2729 was assigned a CVSS score of 9.8, making it a critical vulnerability. This vulnerability is relati
Tenable
CVE-2019-2729: Oracle Releases Out-of-Band Patch for WebLogic Server Deserialization Vulnerability
blogs_tenable·2019-06-19·CVSS 9.8
[CRITICAL] CVE-2019-2729: Oracle Releases Out-of-Band Patch for WebLogic Server Deserialization Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/155886/Oracle-Weblogic-10.3.6.0.0-Remote-Command-Execution.htmlhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2021.htmlhttp://packetstormsecurity.com/files/155886/Oracle-Weblogic-10.3.6.0.0-Remote-Command-Execution.htmlhttp://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2729-5570780.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2021.html
2019-06-19
Published
Exploited in the wild