Feed/CVE-2019-2725
CVE-2019-2725CRITICALCVSS 9.8CISA KEV: Actively Exploited

Oracle WebLogic Server, Injection

Published Jan 10, 2022·Updated Aug 12, 2026

NVD Description

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

Public Exploits & PoCs12 found

[POC] CVE-2019-2725 — CVE-2019-2725

CVE-2019-2725 命令回显

33

[POC] CVE-2019-2725 — CVE-2019-2725

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

33

[POC] CVE-2019-2725 — Weblogic

Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行

33

[POC] CVE-2019-2725 — CVE-2019-2725

weblogic绕过和wls远程执行

33

[POC] CVE-2019-2725 — CVE-2019-2725

CVE-2019-2725命令回显+webshell上传+最新绕过

33

[POC] CVE-2019-2725 — CVE-2019-2725

CVE-2019-2725 bypass pocscan and exp

10

[POC] CVE-2019-2725 — CVE-2019-2725

CVE-2019-2725

4

[POC] CVE-2019-2725 — weblogic_2019_2725_wls_batch

weblogic CVE-2019-2725利用exp。

2

[POC] CVE-2019-2725 — Oracle-WLS-Weblogic-RCE

(CVE-2019-2725) Oracle WLS(Weblogic) RCE test sciript

1

[POC] CVE-2019-2725 — Exploit-CVE-2019-2725

A simple exploit for CVE-2019-2725.

PoC: Oracle-Weblogic-Server-AsyncResponseService-Deserialization-Remote-Code-Execution-CVE-2019-2725

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.

PoC: CVE-2019-2725-POC

CVE-2019-2725-POC

Community Discussion

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free