ZeroHour

CVE-2020-14750

KEVlarge1

Unauthenticated RCE in Oracle WebLogic Server Console (CVE-2020-14750)

CISA: Oracle WebLogic Server Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2020-14750 is a critical vulnerability in the Console component of Oracle WebLogic Server (Oracle Fusion Middleware), functioning as a bypass of the earlier fix for the widely exploited CVE-2020-14882. An unauthenticated attacker with network access over HTTP can trigger it simply by sending crafted requests to the web administration console, with no credentials or user interaction required. Successful exploitation results in full takeover of the WebLogic Server, yielding high impact to confidentiality, integrity and availability (CVSS 3.1 score of 9.8). All supported WebLogic Server versions are affected — 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 — particularly deployments whose admin console is reachable from the internet. Exploitation is confirmed in the wild: the flaw is in CISA's KEV catalog (added 2021-11-03), carries a 99.3% EPSS, and multiple botnets have been observed exploiting it, with reports of access brokers selling compromised-server access to ransomware operators.

What to do: Apply Oracle's emergency/out-of-cycle patch for CVE-2020-14750 or any later Critical Patch Update on all affected WebLogic versions (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0), per vendor instructions. Until patched, restrict HTTP access to the WebLogic admin console to trusted networks and prioritize remediating internet-facing consoles. Hunt for signs of exploitation, since multiple botnets are actively scanning for and exploiting this flaw.

Affected
Oracle WebLogic Server (Console component, Oracle Fusion Middleware)10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Estimated exposure
largetens of thousands of internet-exposed WebLogic servers (total installed base substantially larger) — Public internet scans have consistently indexed on the order of tens of thousands of WebLogic instances with the admin console reachable from the internet, and WebLogic's ubiquity in large enterprise, government and middleware deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle WebLogic Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
weblogic server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news