Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
BID:108074
Info
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
| Bugtraq ID: | 108074 |
| Class: | Serialization Error |
| CVE: |
CVE-2019-2725 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2019 12:00AM |
| Updated: | Jul 17 2019 07:00AM |
| Credit: | Badcode, Liao Xinxi, ZengShuai Hao, Zhiyi Zhang, and Hongwei Pan, Lin Zheng, Song Keya, and Tianlei Li, Xu Yuanzhen |
| Vulnerable: |
Oracle Weblogic Server 12.1.3.0.0 Oracle Weblogic Server 10.3.6.0.0 Oracle Tape Virtual Storage Manager GUI 6.2 Oracle StorageTek Tape Analytics SW Tool 2.3 Oracle Agile PLM 9.3.5 Oracle Agile PLM 9.3.3 Oracle Agile PLM 9.3.4 |
| Not Vulnerable: | |
Discussion
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
Oracle WebLogic Server is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute an arbitrary command within the context of a user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Oracle WebLogic Server 10.3.6.0.0, and 12.1.3.0.0 are vulnerable.
Oracle WebLogic Server is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute an arbitrary command within the context of a user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Oracle WebLogic Server 10.3.6.0.0, and 12.1.3.0.0 are vulnerable.
Exploit / POC
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
Reports indicate that this issue is being exploited in the wild.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Reports indicate that this issue is being exploited in the wild.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
References:
References:
- [KnownSec 404 Team] Oracle WebLogic Deserialization RCE Vulnerability (0day) Ale (Medium)
- CNVD-C-2019-48814 (Github)
- New Oracle WebLogic zero-day discovered in the wild (CBS Interactive)
- Oracle Homepage (Oracle)
- Oracle Weblogic Server Home Page (Oracle)
- Security Bulletin for Deserialized Remote Command Execution Vulnerabilities in O (National Computer Network Emergency Technology Processing Coordination Center)
- Oracle Critical Patch Update Advisory - July 2019 (Oracle)
- Oracle Security Alert Advisory - CVE-2019-2725 (Oracle)