Record summary

CVE-2020-14644 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2020-14644 in KEV.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Sep 18, 2024 · CISA
VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CISA, CVE List12.2.1.3.0affected
12.2.1.4.0affected
14.1.1.0.0affected
CVE List12.2.1.3.0affected
12.2.1.4.0affected
14.1.1.0.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALOracle WebLogic Server - Remote Code Execution (Insecure Deserialization)CVSS 9.8

Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 contain a remote code execution caused by unauthenticated network access via IIOP and T3, letting attackers take over the server, exploit requires network access.

Impact

Attackers can fully compromise the server, leading to data breach, service disruption, and potential control over the system.

Remediation

Apply the latest security patches provided by Oracle for affected versions.

WeaknessesCWE-502
Authorshnd3884
Template tagscvecve2020weblogicrcedeserializationoraclekevvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:oracle:weblogic_server:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:oracle:weblogic_server"
Shodan: product:"WebLogic"
Shodan: http.server:"WebLogic"
Shodan: port:7001
FOFA: product="WebLogic" || header="WebLogic Server"

Source: ProjectDiscovery

References

3