Umbra Wiki cve cve/CVE-2020-14644
Back to wiki

CVE-2020-14644 — Oracle WebLogic Server Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2020-14644

CVE-2020-14644: Oracle WebLogic Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Oracle
Product WebLogic Server
Date added 2024-09-18
Due date 2024-10-09
Ransomware campaign use Unknown

Description

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://www.oracle.com/security-alerts/cpujul2020.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-14644

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-14644
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog