CVE-2019-2725 is a critical deserialization vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware, specifically affecting versions 10.3.6.0.0 and 12.1.3.0.0. This flaw allows unauthenticated attackers with network access via HTTP to achieve full compromise and takeover of the WebLogic Server. With a CVSS v3.0 score of 9.8, it presents a severe risk to confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has readily available exploit code in Metasploit and ExploitDB, alongside significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:* | ||
9.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.4:*:*:*:*:*:*:* | ||
9.3.5CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:* | ||
5.1CPE matchmatch criteria | cpe:2.3:a:oracle:communications_converged_application_server:5.1:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_converged_application_server:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.