Back

CVE-2019-2725

CRITICAL CISA KEV

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Published: Apr 26, 2019 Modified: Aug 12, 2026
CWE-74

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (18)

Vendor Product Version
oracle agile_plm 9.3.3
oracle agile_plm 9.3.4
oracle agile_plm 9.3.5
oracle communications_converged_application_server 5.1
oracle communications_converged_application_server 7.0
oracle communications_converged_application_server 7.1
oracle peoplesoft_enterprise_peopletools 8.56
oracle peoplesoft_enterprise_peopletools 8.57
oracle peoplesoft_enterprise_peopletools 8.58
oracle storagetek_tape_analytics_sw_tool 2.3
oracle tape_library_acsls 8.5
oracle tape_virtual_storage_manager_gui 6.2
oracle vm_virtualbox * < 5.2.36
oracle vm_virtualbox * ≥ 6.0.0 < 6.0.16
oracle vm_virtualbox * ≥ 6.1.0 < 6.1.2
oracle vm_virtualbox 5.2.36
oracle weblogic_server 10.3.6.0.0
oracle weblogic_server 12.1.3.0.0

GitHub Security Advisory GHSA-m437-3crh-7475

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent:...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 99.96%

Top 0% most likely to be exploited

Threat Score 99.2 / 100

CISA Known Exploited

Date Added: 2022-01-10
Due Date: 2022-07-10
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub