CVE-2019-2729 is a critical remote code execution vulnerability in Oracle WebLogic Server's Web Services component, affecting versions 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0. This easily exploitable flaw allows an unauthenticated attacker to compromise and take over the server via HTTP, impacting confidentiality, integrity, and availability with a CVSS v3.0 score of 9.8. While not listed on the CISA KEV catalog, public exploit code exists on ExploitDB and Nuclei templates are available, indicating a high likelihood of exploitation. The vulnerability has garnered significant community discussion and media coverage, emphasizing the urgent need for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_diameter_signaling_router:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:a:oracle:communications_diameter_signaling_router:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2:*:*:*:*:*:*:* | ||
8.2.1CPE matchmatch criteria | cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.1:*:*:*:*:*:*:* | ||
>= 7.3.2, <= 7.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:communications_network_integrity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.