Lucene search

K
cvelistOracleCVELIST:CVE-2019-2890
HistoryOct 16, 2019 - 5:40 p.m.

CVE-2019-2890

2019-10-1617:40:53
oracle
www.cve.org
7

AI Score

7.1

Confidence

High

EPSS

0.249

Percentile

96.7%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CNA Affected

[
  {
    "product": "WebLogic Server",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "10.3.6.0.0"
      },
      {
        "status": "affected",
        "version": "12.1.3.0.0"
      },
      {
        "status": "affected",
        "version": "12.2.1.3.0"
      }
    ]
  }
]

AI Score

7.1

Confidence

High

EPSS

0.249

Percentile

96.7%