cbcvebase.
CVE-2019-2729
published 2019-06-19

CVE-2019-2729: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
88.83%
99.8th percentile
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

22 ranges
VendorProductVersion rangeFixed in
oraclecommunications_diameter_signaling_router
oraclecommunications_diameter_signaling_router
oraclecommunications_diameter_signaling_router
oraclecommunications_diameter_signaling_router
oraclecommunications_network_integrity7.3.2 – 7.3.6
oraclehyperion_infrastructure_technology
oraclehyperion_infrastructure_technology
oracleidentity_manager
oracleidentity_manager
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
oraclerapid_planning
oraclerapid_planning
oraclestoragetek_tape_analytics_sw_tool
oracletape_library_acsls
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

path/_async/*
path/wls-wsat/*
  • Monitor HTTP SOAP requests to /_async/* and /wls-wsat/* URL paths for malicious XML-serialized Java objects (XMLDecoder payloads) — these are the two endpoints that accept WorkContext deserialization input exploited by CVE-2019-2729.
  • Trend Micro Deep Packet Inspection rule 1009816 covers exploitation of CVE-2019-2729 on Oracle WebLogic Server.
  • Trend Micro Deep Discovery Inspector DDI rule 2903 detects possible Oracle WebLogic remote command execution exploit over HTTP.
  • CVE-2019-2729 bypasses the CVE-2019-2725 blacklist by substituting the blacklisted XML tag with a <class> tag — look for SOAP/XMLDecoder payloads containing <class> tags in requests to WebLogic async/wsat endpoints.
  • The exploit leverages UnitOfWorkChangeSet deserialization of an attacker-controlled byte array; detect SOAP requests containing UnitOfWorkChangeSet class references in XMLDecoder payloads.
  • ·Exploitation requires JDK 1.6; WebLogic 10.3.6 ships with JDK 1.6 by default, making it the primary at-risk version for this specific bypass technique.
  • ·Deleting _async.war and wls-wsat.war and restarting the WebLogic service prevents access to the vulnerable URLs as a temporary mitigation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.