PT-2019-2512 · Oracle · Oracle Weblogic Server
Published
2019-06-18
·
Updated
2022-11-10
·
CVE-2019-2729
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle WebLogic Server versions 10.3.6.0.0 through 12.2.1.3.0
Description
The issue is related to the XMLDecoder component of the Oracle WebLogic Server, which has weaknesses in its deserialization mechanism. This can be exploited by a remote attacker to execute arbitrary code, potentially leading to a takeover of the Oracle WebLogic Server. The vulnerability can be easily exploited by an unauthenticated attacker with network access via HTTP.
Recommendations
For versions 10.3.6.0.0, 12.1.3.0.0, and 12.2.1.3.0, update to a patched version to resolve the issue.
As a temporary workaround, consider restricting access to the Web Services subcomponent until a patch is available.
Avoid using the vulnerable XMLDecoder component until the issue is resolved.
Exploit
Fix
Deserialization of Untrusted Data
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Weblogic Server