Sploitus

Exploit for Oracle WebLogic Server deserialization remote code execution

saint Β· 2019-05-02

Exploit Code

MARKDOWN29 lines
## https://sploitus.com/exploit?id=SAINT:37548F7E4861F75CE2B72672750C1CB3
Added: 05/02/2019  
CVE: [CVE-2019-2725](<https://vulners.com/cve/CVE-2019-2725>)  
BID: [108074](<http://www.securityfocus.com/bid/108074>)  


### Background

[Oracle WebLogic Server](<http://www.bea.com/framework.jsp?CNT=index.htm&FP=/content/products/weblogic/>) (formerly BEA WebLogic Server) is a Java web application platform. 

### Problem

Oracle WebLogic Server component of Oracle Fusion Middleware has a deserialization vulnerability in Web Services subcomponent, which allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. 

### Resolution

Apply the patch referenced in the [Oracle Security Alert Advisory - CVE-2019-2725](<https://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html>). 

### References

<https://github.com/fuhei/CNVD-C-2019-48814/blob/master/CNVD-C-2019-48814.py>  


### Limitations

### Platforms

Windows  
Linux