Junglewise Threat Intelligence

CVE-2020-2551: Oracle Fusion Middleware Unspecified Vulnerability

CVE-2020-2551 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-11-16

Technologies: Oracle WebLogic Server, Oracle Fusion Middleware. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the WLS Core Components of Oracle WebLogic Server allows unauthenticated attackers to gain full control of the server via the IIOP protocol. Successful exploitation can result in a complete takeover of the affected Oracle Fusion Middleware instance.

Affected products

  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2020-01-15: disclosed: NVD Published Date
  • 2020-01-15: advisory: Oracle Critical Patch Update Advisory - January 2020
  • 2023-11-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats