CVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected products
- Oracle Weblogic Server
- Oracle Communications Diameter Signaling Router
- = 8.0, 8.1, 8.2, 8.2.1
- Oracle Communications Network Integrity
- ≤ 7.3.6
- Oracle Hyperion Infrastructure Technology
- = 11.1.2.4, 11.2.5.0
- Oracle Identity Manager
- = 11.1.2.3.0, 12.2.1.3.0
- Oracle Peoplesoft Enterprise Peopletools
- = 8.56, 8.57, 8.58
- Oracle Rapid Planning
- = 12.1, 12.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 88.8% (100th percentile)
- Weakness
- CWE-284
- NVD status
- Modified
- Published
- 2019-06-19
CVE-2019-2729 at NVD
17 known exploits for CVE-2019-2729
Proof-of-concept code and exploit modules indexed by Sploitus
Weblogic
CVE-2019-2729
CVE-2019-2729_creal
CVE-2019-2729-Exploit
weblogic-CVE-2019-2729-POC
CVE-2019-2725
weblogicScanner
Exploit for Improper Access Control in Oracle Communications_Diameter_Signaling_Router
Exploit for Improper Access Control in Oracle Communications_Diameter_Signaling_Router
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
Exploit for Improper Access Control in Oracle Communications_Diameter_Signaling_Router
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution Exploit
Oracle Weblogic 10.3.6.0.0 Remote Command Execution
Oracle WebLogic Server Web Services RCE
Exploit for Injection in Oracle Agile_Plm
Exploit for Injection in Oracle Agile_Plm