CVE detail
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
33 source links · newest first
- Old vulnerabilities are still a big problemHelp Net Security
A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →
newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.
vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM- 8220 Gang Cloud Botnet infected 30,000 host globallySecurity Affairs
The crimeware group known as 8220 Gang expanded over the last month their Cloud Botnet to roughly 30,000 hosts globally. Researchers from SentinelOne reported that low-skill crimeware 8220 Gang has expanded their Cloud Botnet over the last month to roughly 30,000 hosts globally. The gang focuses on infecting cloud hosts to deploy cryptocurrency miners by […]
newssecurityaffairs.comJul 21, 2022, 8:06 AM - 4th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 4th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Iranian steel manufacturing plants have suffered a cyberattack which reportedly forced them to halt production. The hacker group Gonjeshke Darande, which has previously attacked the Iranian railway system, assumed responsibility for the […]
vendorresearch.checkpoint.comJul 4, 2022, 11:28 AM - A long-running cryptomining campaign conducted by 8220 hackers now targets Linux serversSecurity Affairs
Microsoft spotted a cloud threat actor tracked as 8220 that is now targeting Linux servers in a long-running cryptomining campaign. Microsoft Security Intelligence experts are warning of a long-running campaign conducted by a cloud threat actor group, tracked as 8220, that is now targeting Linux servers to install crypto miners. “We observed notable updates to […]
newssecurityaffairs.comJul 1, 2022, 2:44 PM The Muhstik botnet has been observed targeting Redis servers exploiting the recently disclosed CVE-2022-0543 vulnerability. Muhstik is a botnet that is known to use web application exploits to compromise IoT devices, it has been around for at least 2018. Botnet operators monetize their efforts via XMRig combined with DDoS-for-hire services. The botnet leverages IRC servers for command-and-control (C2) communications, […]
newssecurityaffairs.comMar 28, 2022, 2:41 PM- DirtyMoe modules expand the bot using worm-like techniquesSecurity Affairs
The DirtyMoe botnet continues to evolve and now includes a module that implements wormable propagation capabilities. In June 2021, researchers from Avast warned of the rapid growth of the DirtyMoe botnet (PurpleFox, Perkiler, and NuggetPhantom), which passed from 10,000 infected systems in 2020 to more than 100,000 in the first half of 2021. Experts defined DirtyMoe as a […]
newssecurityaffairs.comMar 21, 2022, 8:03 AM We provide an overview of known cyberthreats related to Russia-Ukraine cyber activity, including DDoS attacks, HermeticWiper and defacement, and share recommendations for proactive defense.
vendorunit42.paloaltonetworks.comFeb 22, 2022, 11:00 PMUS authorities warn critical infrastructure operators of the threat of cyberattacks orchestrated by Russia-linked threat actors. US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) issued a joint alert to warn critical infrastructure operators about threats from Russian state-sponsored hackers. “This joint Cybersecurity Advisory (CSA)—authored […]
newssecurityaffairs.comJan 12, 2022, 8:01 PMREvil is a ransomware-as-a-service (RaaS) operation that has extorted large amounts of money from organizations worldwide over the past year. Its name stands for Ransomware Evil and was inspired by the Resident Evil movie series. According to recent reports from security firms, it is the most widespread ransomware threat and the group behind it doubles […]
newswww.csoonline.comNov 12, 2021, 10:00 AMThe UK and US cybersecurity agencies have published a report detailing techniques used by Russia-linked cyberespionage group known APT29 (aka Cozy Bear). Today, UK NCSC and CISA-FBI-NSA cybersecurity agencies published a joint security advisory that warns organizations to patch systems immediately to mitigate the risk of attacks conducted by Russia-linked SVR group (aka APT29, Cozy Bear, and The Dukes)). The […]
newssecurityaffairs.comMay 7, 2021, 9:03 PMThis set of ransomware threat assessments is a companion to the Unit 42 Ransomware Threat Report, covering common ransomware families and IOCs.
vendorunit42.paloaltonetworks.comMar 17, 2021, 10:00 AM- Muhstik botnet adds Oracle WebLogic and Drupal exploitsSecurity Affairs
Muhstik botnet leverages known web application exploits to compromise IoT devices, now it targeting Oracle WebLogic, Drupal. Muhstik is a botnet that is known to use web application exploits to compromise IoT devices, it has been around for at least 2018. Botnet operators monetize their efforts via XMRig, combined with DDoS-for-hire services. The botnet leverages IRC servers for command-and-control […]
newssecurityaffairs.comNov 11, 2020, 5:30 PM Unit 42 discovered a new variant of the Muhstik botnet that now adds a scanner to attack Tomato routers for the first time by web authentication brute-forcing.
vendorunit42.paloaltonetworks.comJan 21, 2020, 2:00 PMSince October 2019, Unit 42 has been tracking a new ECHOBOT variant with 71 unique exploits, 13 of which haven’t been previously seen exploited in the wild prior to this version.
vendorunit42.paloaltonetworks.comDec 13, 2019, 9:56 PMSodinokibi ransomware, also known as Sodin and REvil, is hardly three months old, yet it has quickly become a topic of…
newswww.malwarebytes.comJul 17, 2019, 5:00 PM- Oracle’s July 2019 CPU Includes 319 FixesSecurityWeek
Oracle this week published its July 2019 Critical Patch Update (CPU), which brings a total of 319 security fixes across numerous product families. While fewer than 200 of these vulnerabilities can be exploited remotely without authentication, over 50 of them are rated Critical severity, almost all of them featuring a CVSS score of 9.8.
newswww.securityweek.comJul 17, 2019, 11:47 AM Oracle released emergency patches for another critical remote code execution vulnerability affecting WebLogic Server. On Tuesday, Oracle released emergency patches for another critical remote code execution vulnerability affecting the WebLogic Server. The vulnerability, tracked as CVE-2019-2729, affects WebLogic versions 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. The vulnerability is a remotely exploitable deserialization vulnerability via XMLDecoder in Oracle WebLogic […]
newssecurityaffairs.comJun 19, 2019, 11:03 AMOracle on Tuesday announced that it has released emergency patches for a critical remote code execution vulnerability affecting WebLogic Server, a Java EE application server that is part of the company’s Fusion Middleware offering.
newswww.securityweek.comJun 19, 2019, 8:54 AM- Another Oracle WebLogic Server RCE under active exploitationHelp Net Security
Oracle has released an out-of-band fix for CVE-2019-2729, a critical deserialization vulnerability in a number of versions of Oracle WebLogic Server, and is urging customers to apply the security update as soon as possible. Speed is of the essence as, according to KnownSec 404 researchers, the vulnerability is already being exploited in the wild. About the vulnerability (CVE-2019-2729) “This remote code execution vulnerability is remotely exploitable without authentication, i.e., may be exploited over a network … More →
newswww.helpnetsecurity.comJun 19, 2019, 8:34 AM A recently discovered variant of the Mirai Internet of Things (IoT) malware uses a total of 26 different exploits for the infection phase, Akamai reports.
newswww.securityweek.comJun 17, 2019, 8:14 PM- Security Affairs newsletter Round 218 – News of the weekSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy Once again thank you! Critical RCE affects older Diebold Nixdorf ATMs Facebook is going to stop Huawei pre-installing apps on mobile devices Millions of Exim mail servers vulnerable to cyber attacks CIA sextortion […]
newssecurityaffairs.comJun 16, 2019, 5:38 AM The CVE-2019-2725 vulnerability in Oracle WebLogic recently, addressed by the company, is being exploited in cryptojacking attacks, Trend Micro reports. Experts at Trend Micro reported that the recently patched CVE-2019-2725 vulnerability in Oracle WebLogic is being exploited in cryptojacking attacks. The flaw is a deserialization remote command execution zero-day vulnerability that affects the Oracle WebLogic wls9_async and wls–wsat components. The […]
newssecurityaffairs.comJun 11, 2019, 5:53 AMA recently patched vulnerability in Oracle WebLogic is being exploited in attacks aimed at installing crypto-miners on vulnerable machines, Trend Micro reports.
newswww.securityweek.comJun 10, 2019, 5:19 PMOur researchers have discovered a new Mirai variant that uses 8 new vulnerabilities and targets new IoT devices.
vendorunit42.paloaltonetworks.comJun 7, 2019, 12:00 AM- Attackers Increasingly Targeting Oracle WebLogic Server Vulnerability for XMRig and RansomwareUnit42
Unit 42 researchers detail how attacks against the newly patched Oracle Weblogic vulnerability may increase based on details of the vulnerability and analysis of activity seen to date. Research also shows how attackers are using the vulnerability to plant XMRig cryptominer on vulnerable systems.
vendorunit42.paloaltonetworks.comMay 3, 2019, 11:14 PM Attackers are actively exploiting recently fixed vulnerabilities in Oracle WebLogic and the Widget Connector macro in Atlassian Confluence to deliver ransomware, mine cryptocurrency and make the compromised machines participate in DDoS attacks. The Oracle WebLogic attacks CVE-2019-2725 is a deserialization remote command execution vulnerability that affects all Oracle WebLogic versions that have two specific components enabled. It was publicly revealed on April 21 and Oracle published an out-of-band security fix for it on April 25. … More →
newswww.helpnetsecurity.comMay 2, 2019, 10:45 AMA recently observed variant of the Muhstik botnet is exploiting a recently disclosed Oracle WebLogic server vulnerability for cryptomining and distributed denial of service (DDoS) attacks.
newswww.securityweek.comMay 1, 2019, 1:53 PMThreat actors are exploiting a recently patched critical Oracle WebLogic Server vulnerability to deliver the Sodinokibi ransomware to organizations. Threat actors are delivering a new piece of malware, tracked as Sodinokibi, by exploiting a recently patched Oracle WebLogic Server vulnerability. Oracle WebLogic Server is a Java EE application server currently developed by Oracle Corporation, it […]
newssecurityaffairs.comMay 1, 2019, 8:03 AMUnit 42 researchers have found in the wild a new variant of the Muhstik Botnet exploiting the latest WebLogic vulnerability for cryptomining and DDoS attacks. Our latest research provides analysis of these new attacks.
vendorunit42.paloaltonetworks.comApr 30, 2019, 9:15 PMA critical Oracle WebLogic Server vulnerability patched last week has been exploited by malicious actors to deliver a new piece of ransomware to organizations.
newswww.securityweek.comApr 30, 2019, 5:44 PMOracle has released an out-of-band update for WebLogic Server, a Java EE application server that is part of the company’s Fusion Middleware offering, to patch a zero-day vulnerability exploited in the wild by malicious actors.
newswww.securityweek.comApr 29, 2019, 12:53 PM- Researchers flag new Oracle WebLogic zero-day RCE flawHelp Net Security
Attackers looking to compromise Oracle WebLogic servers for their own needs have a new zero-day RCE flaw at their disposal. “Oracle WebLogic wls9_async and wls-wsat components trigger deserialization remote command execution vulnerability. This vulnerability affects all Weblogic versions (including the latest version) that have the wls9_async_response.war and wls-wsat.war components enabled,” KnownSec 404 researchers warn. The flaw has been reported to Oracle, but is yet to receive a CVE number. It can be currently tracked under … More →
newswww.helpnetsecurity.comApr 25, 2019, 1:25 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2019-2729CVSS 9.8 · Critical
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and…
- CVE-2021-40690CVSS 7.5 · High
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when cre…
- CVE-2018-1000613CVSS 9.8 · Critical
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select C…
- CVE-2018-1000180CVSS 7.5 · High
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-…
- CVE-2021-44832CVSS 6.6 · Medium
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses…
- CVE-2017-15708CVSS 9.8 · Critical
In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.…