Enhancement: cves/2019/CVE-2019-2725.yaml by mp

patch-1
MostInterestingBotInTheWorld 2022-05-03 13:00:20 -04:00
parent 56b6283fd6
commit 2831440ea5
1 changed files with 6 additions and 3 deletions

View File

@ -1,15 +1,16 @@
id: CVE-2019-2725
info:
name: Oracle WebLogic Server - Unauthenticated RCE
name: Oracle WebLogic Server - Remote Command Execution
author: dwisiswant0
severity: critical
description: |
Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) allows unauthenticated attackers with network access via HTTP to compromise Oracle WebLogic Server. Versions that are affected are 10.3.6.0.0 and 12.1.3.0.0.
reference:
- https://paper.seebug.org/910/
- https://www.exploit-db.com/exploits/46780/
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://nvd.nist.gov/vuln/detail/CVE-2019-2725
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
@ -42,4 +43,6 @@ requests:
part: header
- type: status
status:
- 200
- 200
# Enhanced by mp on 2022/05/03