Insecure deserialization in Oracle WebLogic Server - CVE-2019-2725
Published: April 26, 2019 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insecure deserialization of untrusted data within the "wls9_async_response.war" and "wls-wsat.war" components. A remote non-authenticated attacker can send a specially crafted HTTP request to "/_async/*" and "/wls-wsat/*" URLs and execute arbitrary code on the target system.
Affected software
StorageTek Tape Analytics SW Tool
Tape Virtual Storage Manager GUI
Tape Library ACSLS
Oracle Agile PLM Framework
How to mitigate CVE-2019-2725
Links to Public Exploits and PoC-codes
- Exploit #6020 - Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit) (June 17, 2021)
- Exploit #5931 - Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution (June 17, 2021)
- Exploit #238 - CVE-2019-2725 (WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit ) (March 18, 2020)