January 10, 2022 · Applied Cybernetics Group
CVE-2019-2725 — Oracle WebLogic Server
known ransomware use
Oracle WebLogic Server, Injection
- Added to KEV
2022-01-10- Federal due date
2022-07-10- Vendor
- Oracle
- Product
- WebLogic Server
- EPSS
- 100.0th percentile (score 1.000, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-2725
CISA short description
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
Required action
Apply updates per vendor instructions.
NVD description
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).