CVE-2019-2725

CVE Published 2019-04-26
Related CWE(s) CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Related Vendor(s) oracle
Related Product(s) peoplesoft_enterprise_peopletools, tape_virtual_storage_manager_gui, tape_library_acsls, agile_plm, vm_virtualbox, storagetek_tape_analytics_sw_tool, weblogic_server, communications_converged_application_server
Exploitation Reported (CISA KEV) 2022-01-10
CVSS 3 Base Score 7.5 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References