Executive brief
Oracle WebLogic Server contains a remote code execution vulnerability in the Console component. An unauthenticated attacker can exploit this via HTTP to gain full control of the server. This vulnerability is related to CVE-2020-14882 and has been observed being exploited in the wild.
Affected products
- Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Timeline
- 2020-11-02: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-11-19: patched: Oracle security alert and patch released