CVE-2019-2725
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Oracle WebLogic Server, Injection
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-74
מוצרים מושפעים
oracle: agile plm; oracle: communications converged application server; oracle: peoplesoft enterprise peopletools; oracle: storagetek tape analytics sw tool; oracle: tape library acsls; oracle: tape virtual storage manager gui; oracle: vm virtualbox; oracle: weblogic server
קישורים
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-546629… PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchVendor Advisory
- https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW PatchVendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-546629… PatchVendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchVendor Advisory
- https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW PatchVendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html PatchVendor Advisory
- https://www.exploit-db.com/exploits/46780/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46780/ ExploitThird Party AdvisoryVDB Entry