5.3
CVSSv3

CVE-2019-2888

Published: 16/10/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: EJB Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle weblogic server 10.3.6.0.0

oracle weblogic server 12.1.3.0.0

oracle weblogic server 12.2.1.3.0

Github Repositories

《Web安全教程之XXE漏洞》XML External Entity Injection.

《深入理解WEB漏洞之XXE漏洞》 本项目用来收集整理XXE漏洞的相关内容,包括XXE的利用方法工具或思路等。XXE漏洞往往不可以执行命令,但可以通过文件读取方法获取敏感信息,之后进一步Getshell!作者:0e0w 本项目创建于2022年3月3日,最近的一次更新时间为2024年3月1日。本项目会持续更新

WebLogic EJBTaglibDescriptor XXE漏洞(CVE-2019-2888)

CVE-2019-2888 WebLogic EJBTaglibDescriptor XXE漏洞 wwworaclecom/security-alerts/cpuoct2019