CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 100%
- Percentil entre todas las CVEs puntuadas: 100
- Fecha de la puntuación: 29/9/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CISA KEV — explotada activamente
- Añadida al catálogo: 10/1/2022
- Plazo de remediación: 10/7/2022
- Uso conocido en ransomware: Known
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto secundario
T1565.001Stored Data Manipulationimpact80 %
Vulnerabilidad crítica en WebLogic (AV:N, PR:N, UI:N) explotable remotamente sin autenticación. Permite compromiso total del servidor, implicando ejecución de código remoto, toma de cuentas y manipulación de datos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (8)
CWE
- CWE-74
Referencias
- http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.securityfocus.com/bid/108074
- https://support.f5.com/csp/article/K90059138
- https://www.exploit-db.com/exploits/46780/
- https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
- https://www.oracle.com/security-alerts/cpujan2020.html
- http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
- http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- http://www.securityfocus.com/bid/108074
- https://support.f5.com/csp/article/K90059138
- https://www.exploit-db.com/exploits/46780/
- https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2725
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-2725",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2019-2725",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-12T03:55:17.934499Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "secalert_us@oracle.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert_us@oracle.com",
"affectedData": [
{
"vendor": "Oracle Corporation",
"product": "Tape Library ACSLS",
"versions": [
{
"status": "affected",
"version": "8.5"
}
]
}
]
}
],
"published": "2019-04-26T19:29:00.463",
"references": [
{
"url": "http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert_us@oracle.com"
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "http://www.securityfocus.com/bid/108074",
"tags": [
"Broken Link"
],
"source": "secalert_us@oracle.com"
},
{
"url": "https://support.f5.com/csp/article/K90059138",
"tags": [
"Third Party Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "https://www.exploit-db.com/exploits/46780/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert_us@oracle.com"
},
{
"url": "https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2020.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/108074",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.f5.com/csp/article/K90059138",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/46780/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2020.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2725",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-74"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
},
{
"lang": "es",
"value": "Vulnerabilidad en el componente Oracle WebLogic Server de Oracle Fusion Middleware (subcomponente: Web Services). Las versiones afectadas son la 10.3.6.0.0 y la 12.1.3.0.0.0. Una vulnerabilidad fácilmente explotable permite que un atacante no autenticado con acceso a la red a través de HTTP ponga en peligro Oracle WebLogic Server. Los ataques con éxito de esta vulnerabilidad pueden dar lugar a la adquisición de Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Impactos de Confidencialidad, Integridad y Disponibilidad). Vector CVSS: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)"
}
],
"lastModified": "2026-10-01T21:17:15.087",
"cisaActionDue": "2022-07-10",
"cisaExploitAdd": "2022-01-10",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8C893E4-1D3A-4687-BE5A-D26FFEBCCC78"
},
{
"criteria": "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "18260EE8-9BC0-4BA1-9642-90FE052E8B18"
},
{
"criteria": "cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0BB81C3-29FD-4AE0-8D46-456FAF135F6C"
},
{
"criteria": "cpe:2.3:a:oracle:communications_converged_application_server:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90AF4292-8262-4266-8451-D8DDCD32D3D4"
},
{
"criteria": "cpe:2.3:a:oracle:communications_converged_application_server:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B91E2BCF-005C-4B63-8FDF-5EB4AD9D37D1"
},
{
"criteria": "cpe:2.3:a:oracle:communications_converged_application_server:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A10A101-638F-4A0F-89B2-1202AC991B19"
},
{
"criteria": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0A735B4-4F3C-416B-8C08-9CB21BAD2889"
},
{
"criteria": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E1E416B-920B-49A0-9523-382898C2979D"
},
{
"criteria": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D9DB4A14-2EF5-4B54-95D2-75E6CF9AA0A9"
},
{
"criteria": "cpe:2.3:a:oracle:storagetek_tape_analytics_sw_tool:2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E55B3AA9-69BE-4136-8C3A-FD0DDCD3FA4B"
},
{
"criteria": "cpe:2.3:a:oracle:tape_library_acsls:8.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "162C6FD9-AEC2-4EBA-A163-3054840B8ACE"
},
{
"criteria": "cpe:2.3:a:oracle:tape_virtual_storage_manager_gui:6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE644844-8492-443E-9FA2-49D92DB3F887"
},
{
"criteria": "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E8A63B7-DBEE-46CB-905B-F98C7B1B4572",
"versionEndExcluding": "5.2.36"
},
{
"criteria": "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64D449F8-D58F-4D15-9478-ECDE495153C5",
"versionEndExcluding": "6.0.16",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A85E19DF-6CA3-40AD-9D04-71E478F4C7D5",
"versionEndExcluding": "6.1.2",
"versionStartIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:oracle:vm_virtualbox:5.2.36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "940EF267-1AD3-4240-9696-0B16CC406C47"
},
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B40B13B7-68B3-4510-968C-6A730EB46462"
},
{
"criteria": "cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C93CC705-1F8C-4870-99E6-14BF264C3811"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert_us@oracle.com",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Oracle WebLogic Server, Injection"
}