Executive brief
Oracle WebLogic Server contains a deserialization vulnerability in its Core component. Unauthenticated attackers can exploit this via the T3 or IIOP protocols to achieve full remote code execution and take over the server.
Affected products
- Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2020-07-15: disclosed: NVD Published Date
- 2020-07-15: advisory: Oracle Critical Patch Update Advisory - July 2020
- 2024-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-18: exploited: Confirmed exploitation in the wild per CISA KEV entry