Junglewise Threat Intelligence

CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

CVE-2020-14644 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-18

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains a deserialization vulnerability in its Core component. Unauthenticated attackers can exploit this via the T3 or IIOP protocols to achieve full remote code execution and take over the server.

Affected products

  • Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2020-07-15: disclosed: NVD Published Date
  • 2020-07-15: advisory: Oracle Critical Patch Update Advisory - July 2020
  • 2024-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-18: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats