EXPOSURES › CVE-2019-2725
CVE-2019-2725
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.
A critical injection vulnerability in Oracle WebLogic Server allowed attackers to potentially compromise systems. This poses a significant risk to DIB organizations relying on WebLogic, potentially leading to data breaches and ransomware infections; immediate patching and security review are essential.
Shame score — The vulnerability's active exploitation and ransomware linkage demonstrate a serious failure to maintain security, particularly given Oracle's size and resources.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |