S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-14882 Scanner

CVE-2020-14882 scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-14882
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
10.3.6.0.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebLogic Server is an application server used for hosting business applications and web services. It provides a reliable and scalable environment for running Java-based applications and enables integration with other enterprise systems. WebLogic Server is widely used by large-scale organizations for running critical applications, and any vulnerability in this software can have serious consequences.

One such vulnerability is CVE-2020-14882, which was detected in the Console component of Oracle WebLogic Server. This vulnerability can be easily exploited by an unauthenticated attacker with network access through HTTP. The affected versions of the software are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.

When exploited, this vulnerability can lead to a complete takeover of Oracle WebLogic Server, compromising the confidentiality, integrity, and availability of business-critical systems. An attacker can execute arbitrary code on the server and gain full control of the system, allowing them to access sensitive data, modify application configurations, and even shut down the server.

s4e.io is a comprehensive security platform that offers pro features to help organizations protect their digital assets. With features such as vulnerability scanning, threat intelligence, and incident response, users can easily and quickly identify vulnerabilities in their systems and take appropriate actions to mitigate them. By subscribing to s4e.io, users can rest assured that their systems are protected against the latest security threats.

 

REFERENCES

 

Solution Advice

To protect against this vulnerability, organizations are advised to take the following precautions:

  • Apply the latest security patches provided by Oracle as soon as possible.
  • Implement network segmentation to restrict access to the affected systems.
  • Use strong access controls and authentication mechanisms to restrict access to the server.
  • Monitor network traffic and system logs for any suspicious activity.
  • Consider using a web application firewall to block exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.