Deserialization of Untrusted Data in Oracle WebLogic Server - CVE-2019-2729
Published: June 20, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data within XMLDecoder class. A remote non-authenticated attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: this vulnerability is being actively exploited in the wild.
Affected software
Oracle Communications Converged Application Server
StorageTek Tape Analytics SW Tool
Oracle Communications Network Integrity
Oracle Communications Diameter Signaling Router (DSR)
Infrastructure Technology
Tape Library ACSLS
PeopleSoft Enterprise PeopleTools
How to mitigate CVE-2019-2729
Links to Public Exploits and PoC-codes
- Exploit #5813 - Oracle Weblogic 10.3.6.0.0 - Remote Command Execution (June 17, 2021)
- Exploit #2617 - Weblogic-and-Go (This is a simple tool that use a scanner and an specific exploit for CVE-2019-2729. ) (April 29, 2020)
- Exploit #2185 - CVE-2019-2725 (WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit ) (March 18, 2020)
- Exploit #261 - CVE-2019-2729 (Exploit code for CVE-2019-2729) (March 18, 2020)
- Exploit #262 - CVE-2019-2729-Exploit (CVE-2019-2729 Exploit Script) (March 18, 2020)
External References
Related Security Bulletins
- Remote code execution in Oracle WebLogic Server
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router (DSR)
- Multiple vulnerabilities in StorageTek Tape Analytics SW Tool
- Multiple vulnerabilities in Tape Library ACSLS
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Oracle Communications Network Integrity
- Multiple vulnerabilities in Hyperion Infrastructure Technology
- Deserialization of Untrusted Data in Oracle Communications Converged Application Server
- Multiple vulnerabilities in StorageTek Tape Analytics SW Tool