Junglewise Threat Intelligence

CVE-2020-14882: Oracle WebLogic Server Remote Code Execution Vulnerability

CVE-2020-14882 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle WebLogic Server. Vendors: Oracle.

Executive brief

A vulnerability in the Console component of Oracle WebLogic Server allows unauthenticated attackers with network access via HTTP to compromise the server. Successful exploitation can lead to remote code execution and a complete takeover of the affected WebLogic Server instance.

Affected products

  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0

Timeline

  • 2020-10-21: advisory: Oracle Critical Patch Update Advisory - October 2020
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: Publication date listed in advisory summary

Related threats