S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-14883 Scanner

CVE-2020-14883 scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-14883
7.2
CVSShigh
Exploitable remotely over the internet · requires high privileges.

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
10.3.6.0.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebLogic Server is a popular application server used by enterprises for running business-critical applications. It is widely used for creating, deploying, and managing Java EE applications across distributed environments. The product allows developers to streamline the application development lifecycle with easy-to-use tools and an open, standards-based platform. Oracle WebLogic Server is designed to be a robust and reliable platform that delivers high availability and scalability for enterprise applications.

Recently, a vulnerability with the code CVE-2020-14883 has been detected in Oracle WebLogic Server. The vulnerability is easily exploitable and can be used by high privileged attackers with network access via HTTP to compromise the server. The vulnerability affects several versions of the product, including 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. The CVSS 3.1 base score of the vulnerability is 7.2, which indicates that the vulnerability can have serious Confidentiality, Integrity and Availability impacts.

When exploited, CVE-2020-14883 can result in a takeover of Oracle WebLogic Server. This can lead to significant data breaches, information theft, and system damage. Attackers can use this vulnerability to execute arbitrary code and take control of the server. This can result in the attacker gaining privileged access to the target network and exposing sensitive information to malicious actors. As a result, businesses must take steps to protect their systems from this vulnerability.

Thanks to the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their digital assets. By using the platform, businesses can stay up-to-date on the latest cybersecurity threats and vulnerabilities affecting their systems. This can help businesses proactively identify and mitigate security risks before they turn into serious security incidents. By taking a proactive approach to cybersecurity, businesses can better protect their digital assets and safeguard their operations from cyber threats.

 

REFERENCES

Solution Advice

Businesses can take several precautions to protect against the CVE-2020-14883 vulnerability. These include:

  • Patching the affected versions of Oracle WebLogic Server as soon as possible
  • Configuring firewalls and access controls to prevent unauthorized access to the server
  • Monitoring the network for suspicious activity and unusual traffic patterns
  • Implementing multi-factor authentication to prevent unauthorized access to the server
  • Following security best practices and guidelines to mitigate the risk of attacks

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-14883 scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server S4E