ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Oracle To Address 320 Vulnerabilities in January Patch Update

criticalVulnerability exploited in the wildimportance 60CVE-2020-2883

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2883
Unauthenticated RCE in Oracle WebLogic Server via T3/IIOP

CVE-2020-2883 is an easily exploitable, unauthenticated vulnerability in the Core component of Oracle WebLogic Server that is reachable over the network via the T3 and IIOP protocols. An attacker with network access to a WebLogic listener can trigger the flaw without credentials or user interaction, and successful exploitation results in takeover of Oracle WebLogic Server, with high confidentiality, integrity, and availability impact. The supported affected releases are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Oracle rates the flaw CVSS 9.8 (Critical), and it carries a very high EPSS of 94.9% (100th percentile), indicating near-certain near-term exploitation likelihood. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 amid active exploitation, with reports of hackers targeting WebLogic servers and the flaw included in Oracle's January 2025 patch cycle.

Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server — Oracle's January 2025 patch release includes WebLogic fixes, and the affected releases (10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0) must be patched per vendor instructions. Until patched, restrict network access to the T3 and IIOP listeners (e.g., firewall them to trusted hosts only), prioritize internet-facing instances, and hunt for signs of exploitation. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.895% KEV
  • Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
largetens of thousands of internet-exposed WebLogic instances
Full article228 words · extracted from infosecurity-magazine.com · click to collapse

Software giant Oracle is expected to release patches for 320 new security vulnerabilities affecting over 90 products and services across 27 categories.

These categories include Oracle’s Communications applications and executives, Construction and Engineering appliances, middleware and servers, and products and services part of the Oracle E-Business Suite.

According to a pre-release announcement, the concerned vulnerabilities range from low  – with some being attributed CVSS scores between 4 and 6 – to critical severity.

The most critical flaws, with a CVSS score of 9.9, affect the Oracle Supply Chain product range, namely Oracle Agile Engineering Data Management version 6.2.1 and Oracle Agile PLM Framework version 9.3.6.

At least five other vulnerabilities have been allocated a 9.8 CVSS score, suggesting high severity.

Read more about updates: Software Updates, A Double-Edged Sword for Cybersecurity Professionals

The finalized January 2025 Critical Patch Update is scheduled for release on January 21.

“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update patches as soon as possible,” the pre-release announcement said.

Earlier in January, the US Cybersecurity and Infrastructure Security Agency (CISA) added an older vulnerability in Oracle WebLogic Server (CVE-2020-2883) to its Known Exploited Vulnerabilities (KEV) catalog, showing that five-year-old Oracle flaws are still left unpatched on some networks.

Read now: Apple Issues Emergency Security Update for Actively Exploited Vulnerabilities

Photo credits: JHVEPhoto/Danille Nicole Wilson/Shutterstock

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/oracle-320-vulnerabilities-january/