Oracle WebLogic Server是美国甲骨文(Oracle)公司的一款适用于云环境和传统环境的应用服务中间件,它提供了一个现代轻型开发平台,支持应用从开发到生产的整个生命周期管理,并简化了应用的部署和管理。 Oracle Fusion Middleware中的WebLogic Server组件10.3.6.0.0版本、12.1.3.0.0版本和12.2.1.3.0版本的Web Services子组件存在访问控制错误漏洞。攻击者可利用该漏洞控制组件,影响数据的保密性和可用性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Oracle Corporation | WebLogic Server | 10.3.6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit code for CVE-2019-2729 | https://github.com/waffl3ss/CVE-2019-2729 | POC Details |
| 2 | CVE-2019-2729 Exploit Script | https://github.com/ruthlezs/CVE-2019-2729-Exploit | POC Details |
| 3 | PoC for exploiting CVE-2019-2729 on WebLogic | https://github.com/Luchoane/CVE-2019-2729_creal | POC Details |
| 4 | The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versions 0.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0 contain an easily exploitable vulnerability that allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-2729.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet