Junglewise Threat Intelligence

CVE-2020-14750: Oracle WebLogic Server Remote Code Execution Vulnerability

CVE-2020-14750 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

Oracle WebLogic Server contains a remote code execution vulnerability in the Console component. An unauthenticated attacker can exploit this via HTTP to gain full control of the server. This vulnerability is related to CVE-2020-14882 and has been observed being exploited in the wild.

Affected products

  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2020-11-02: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-11-19: patched: Oracle security alert and patch released

Related threats