Lucene search

K
f5F5F5:K90059138
HistoryApr 30, 2019 - 12:00 a.m.

K90059138 : Oracle WebLogic Deserialization Remote Code Execution CVE-2019-2725

2019-04-3000:00:00
my.f5.com
697

9.8 High

AI Score

Confidence

High

0.976 High

EPSS

Percentile

100.0%

Security Advisory Description

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). (CVE-2019-2725)

Impact

There is no impact; F5 products are not affected by this vulnerability.