peter bassill · operator
$ cve CVE-2019-2729 JSON

CVE-2019-2729 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 88.8% (pctl 100)

Patch early

A public exploit exists.

Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.83% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2019-06-19
Last modified2026-06-17

Affected (9)

VendorProduct
oraclecommunications diameter signaling router
oraclecommunications network integrity
oraclehyperion infrastructure technology
oracleidentity manager
oraclepeoplesoft enterprise peopletools
oraclerapid planning
oraclestoragetek tape analytics sw tool
oracletape library acsls
oracleweblogic server

Public exploits

SourceTitleDate
exploit-dbOracle Weblogic 10.3.6.0.0 - Remote Command Execution2020-01-09

References

→ the Explorer  ·  watch your stack  ·  NVD