Insecure deserialization in Oracle WebLogic Server - CVE-2019-2725

 

Insecure deserialization in Oracle WebLogic Server - CVE-2019-2725

Published: April 26, 2019 / Updated: February 20, 2022


Vulnerability identifier: #VU18354
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2725
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insecure deserialization of untrusted data within the "wls9_async_response.war" and "wls-wsat.war" components. A remote non-authenticated attacker can send a specially crafted HTTP request to "/_async/*" and "/wls-wsat/*" URLs and execute arbitrary code on the target system.


Affected software

Oracle WebLogic Server
StorageTek Tape Analytics SW Tool
Tape Virtual Storage Manager GUI
Tape Library ACSLS
Oracle Agile PLM Framework

How to mitigate CVE-2019-2725

Install patch from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins