critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-2725 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Oracle WebLogic Server affects v. 10.3.6.0.0 and 12.1.3.0.0.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
12
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2019-2725
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Tape Library ACSLSby Oracle Corporation
8.5
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebLogic Server, commonly abbreviated as WLS, is a powerful application server used by developers and enterprises to deploy, run, and manage Java-based applications. As an essential component of Oracle Fusion Middleware, WLS is designed to provide a reliable, scalable, and secure infrastructure that supports critical business operations. With its advanced features, including clustering, load-balancing, and high availability, WLS is widely adopted in various industries such as finance, healthcare, and government.

However, the recent discovery of the CVE-2019-2725 vulnerability in WLS has raised concerns about the security of this popular platform. This vulnerability, which affects versions 10.3.6.0.0 and 12.1.3.0.0, allows an attacker to remotely compromise the WLS server without requiring any authentication or user interaction. The vulnerability is caused by a flaw in the XMLDecoder component of the Web Services subcomponent, which fails to properly handle certain input data.

If this vulnerability is successfully exploited, it can result in a complete takeover of the WLS server. The attacker can gain complete control over the server, access sensitive data, modify or delete data, and launch further attacks to compromise other parts of the network. Given the severity of this vulnerability, it is critical that organizations take immediate action to protect their assets.

At s4e.io, we are dedicated to providing comprehensive and up-to-date information about vulnerabilities that may affect your digital assets. With our pro features, you can quickly and easily learn about the latest security threats and take immediate action to protect your systems. Sign up today and stay ahead of the hackers!

 

REFERENCES

Solution Advice

To protect against the CVE-2019-2725 vulnerability, the following precautions can be taken:

  • Apply the latest security patches and updates from Oracle.
  • Disable access to the T3 protocol, which is used by WLS, if not required.
  • Implement network segmentation and firewalls to restrict access to the WLS server.
  • Monitor network traffic for any suspicious activities that may indicate an attack.
  • Use intrusion detection and prevention systems to detect and block known attack patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-2725 scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server S4E