---
id: CVE-2019-2725
title: >-
  Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
  Middleware (subcomponent: Web Services)
summary: >-
  Vulnerability in the Oracle WebLogic Server component of Oracle Fusion
  Middleware (subcomponent: Web Services). Supported versions that are affected
  are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows
  unauthenticated a…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-74
vendor: oracle
product: agile_plm
affected:
  - agile_plm = 9.3.3
  - agile_plm = 9.3.4
  - agile_plm = 9.3.5
  - communications_converged_application_server = 5.1
  - communications_converged_application_server = 7.0
  - communications_converged_application_server = 7.1
  - peoplesoft_enterprise_peopletools = 8.56
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - storagetek_tape_analytics_sw_tool = 2.3
  - tape_library_acsls = 8.5
  - tape_virtual_storage_manager_gui = 6.2
  - vm_virtualbox < 5.2.36
  - 'vm_virtualbox >= 6.0.0, < 6.0.16'
  - 'vm_virtualbox >= 6.1.0, < 6.1.2'
  - vm_virtualbox = 5.2.36
  - weblogic_server = 10.3.6.0.0
  - weblogic_server = 12.1.3.0.0
patched:
  - vm_virtualbox 6.1.2
published: '2019-04-26'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-2725'
references:
  - url: >-
      http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
    label: secalert_us@oracle.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html
    label: secalert_us@oracle.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: secalert_us@oracle.com
  - url: 'http://www.securityfocus.com/bid/108074'
    label: secalert_us@oracle.com
  - url: 'https://support.f5.com/csp/article/K90059138'
    label: secalert_us@oracle.com
  - url: 'https://www.exploit-db.com/exploits/46780/'
    label: secalert_us@oracle.com
  - url: >-
      https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
    label: secalert_us@oracle.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: secalert_us@oracle.com
  - url: >-
      http://packetstormsecurity.com/files/152756/Oracle-Weblogic-Server-Deserialization-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/alert-cve-2019-2725-5466295.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/108074'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.f5.com/csp/article/K90059138'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/46780/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.oracle.com/security-alerts/alert-cve-2019-2725.html#AppendixFMW
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2725
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99964
epssPercentile: 0.99976
kev: true
kevDateAdded: '2022-01-10'
kevDueDate: '2022-07-10'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-12T05:52:07.052Z'
exploits:
  exploitdb: true
  github: 19
  githubRepos:
    - 'https://github.com/shack2/javaserializetools'
    - 'https://github.com/SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961'
    - 'https://github.com/lasensio/cve-2019-2725'
  metasploit:
    - exploit/multi/misc/weblogic_deserialize_asyncresponseservice
  nuclei:
    - CVE-2019-2725
  checkedAt: '2026-09-19T16:22:50.751Z'
---

## Overview

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `agile_plm = 9.3.3`
- `agile_plm = 9.3.4`
- `agile_plm = 9.3.5`
- `communications_converged_application_server = 5.1`
- `communications_converged_application_server = 7.0`
- `communications_converged_application_server = 7.1`
- `peoplesoft_enterprise_peopletools = 8.56`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `storagetek_tape_analytics_sw_tool = 2.3`
- `tape_library_acsls = 8.5`
- `tape_virtual_storage_manager_gui = 6.2`
- `vm_virtualbox < 5.2.36`
- `vm_virtualbox >= 6.0.0, < 6.0.16`
- `vm_virtualbox >= 6.1.0, < 6.1.2`
- `vm_virtualbox = 5.2.36`
- `weblogic_server = 10.3.6.0.0`
- `weblogic_server = 12.1.3.0.0`

## Remediation

Upgrade past the affected range:

- `vm_virtualbox 6.1.2`
