ZeroHour

CVE-2020-2883

KEVlarge

Unauthenticated RCE in Oracle WebLogic Server via T3/IIOP

CISA: Oracle WebLogic Server Unspecified Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2020-2883 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle WebLogic Server that is reachable over the network via the T3 and IIOP protocols. An attacker with network access to a WebLogic listener can trigger the flaw without credentials or user interaction, and successful exploitation results in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact. The supported affected releases are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Oracle rates the flaw CVSS 9.8 (Critical), and it carries a very high EPSS of 94.9% (100th percentile), indicating near-certain near-term exploitation likelihood. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 amid active exploitation, with reports of hackers targeting WebLogic servers and the flaw included in Oracle's January 2025 patch cycle.

What to do: Apply the Oracle Critical Patch Update fixes for WebLogic Server — Oracle's January 2025 patch release includes WebLogic fixes, and the affected releases (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0) must be patched per vendor instructions. Until patched, restrict network access to the T3 and IIOP listeners (e.g., firewall them to trusted hosts only), prioritize internet-facing instances, and hunt for signs of exploitation. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Affected
Oracle WebLogic Server10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
Estimated exposure
largetens of thousands of internet-exposed WebLogic instances — Public internet-wide scan services (e.g., Shodan/Censys) have long shown on the order of tens of thousands of exposed WebLogic T3/IIOP endpoints, and WebLogic is a staple of large enterprise, financial, and government Java deployments, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle WebLogic Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
weblogic server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news