Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2019-2725
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle Fusion Middleware WebLogic Server组件访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle Fusion Middleware(Oracle融合中间件)是美国甲骨文(Oracle)公司的一套面向企业和云环境的业务创新平台。该平台提供了中间件、软件集合等功能。WebLogic Server是其中的一个适用于云环境和传统环境的应用服务器组件。 部分版本WebLogic中默认包含的wls9_async_response包,为WebLogicServer提供异步通讯服务。由于该WAR包在反序列化处理输入信息时存在缺陷,攻击者可以发送精心构造的恶意HTTP请求,获得目标服务器的权限,在未授权
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Oracle CorporationTape Library ACSLS 8.5 -
II. Public POCs for CVE-2019-2725
#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/iceMatcha/CNTA-2019-0014xCVE-2019-2725POC Details
2Nonehttps://github.com/lasensio/cve-2019-2725POC Details
3Nonehttps://github.com/davidmthomsen/CVE-2019-2725POC Details
4Nonehttps://github.com/leerina/CVE-2019-2725POC Details
5Nonehttps://github.com/zhusx110/cve-2019-2725POC Details
6CVE-2019-2725 命令回显https://github.com/lufeirider/CVE-2019-2725POC Details
7CVE-2019-2725命令回显+webshell上传+最新绕过https://github.com/TopScrew/CVE-2019-2725POC Details
8Nonehttps://github.com/welove88888/CVE-2019-2725POC Details
9weblogic绕过和wls远程执行https://github.com/jiansiting/CVE-2019-2725POC Details
10CVE-2019-2725 bypass pocscan and exp https://github.com/kerlingcode/CVE-2019-2725POC Details
11Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行 https://github.com/black-mirror/WeblogicPOC Details
12WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit https://github.com/pimps/CVE-2019-2725POC Details
13CVE-2019-2725https://github.com/ianxtianxt/CVE-2019-2725POC Details
14CVE-2019-2725-POChttps://github.com/N0b1e6/CVE-2019-2725-POCPOC Details
15weblogic CVE-2019-2725利用exp。https://github.com/GGyao/weblogic_2019_2725_wls_batchPOC Details
16(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciripthttps://github.com/ludy-dev/Oracle-WLS-Weblogic-RCEPOC Details
17Nonehttps://github.com/1stPeak/CVE-2019-2725-environmentPOC Details
18A simple exploit for CVE-2019-2725.https://github.com/CalegariMindSec/Exploit-CVE-2019-2725POC Details
19Nonehttps://github.com/Kamiya767/CVE-2019-2725POC Details
20Nonehttps://github.com/tobechenghuai/CNTA-2019-0014xCVE-2019-2725POC Details
21The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2725.yamlPOC Details
22Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Weblogic%20XMLDecoder%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2019-2725.mdPOC Details
23Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.https://github.com/loursha/Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2019-2725
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2019-2725

No comments yet


Leave a comment