CVE-2020-14644
Oracle WebLogic Server Remote Code Execution Vulnerability
Record summary
CVE-2020-14644 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template. CISA lists CVE-2020-14644 in KEV.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploitation context
Known exploitation
- CISA KEV
- Listed · Sep 18, 2024 · CISA
- VulnCheck KEV
- Listed · Sep 18, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WebLogic ServerBrowse Oracle / WebLogic ServerDefault status: unknown | CISA, CVE List | 12.2.1.3.0 | affected |
| 12.2.1.4.0 | affected | ||
| 14.1.1.0.0 | affected | ||
WebLogic ServerBrowse Oracle Corporation / WebLogic Server | CVE List | 12.2.1.3.0 | affected |
| 12.2.1.4.0 | affected | ||
| 14.1.1.0.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALOracle WebLogic Server - Remote Code Execution (Insecure Deserialization)CVSS 9.8
Oracle WebLogic Server 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 contain a remote code execution caused by unauthenticated network access via IIOP and T3, letting attackers take over the server, exploit requires network access.
Impact
Attackers can fully compromise the server, leading to data breach, service disruption, and potential control over the system.
Remediation
Apply the latest security patches provided by Oracle for affected versions.
Source: ProjectDiscovery