S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Nov 6, 2025

CVE-2020-14644 Scanner

CVE-2020-14644 Scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-14644
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WebLogic Serverby Oracle Corporation
12.2.1.3.0
weblogic_serverby oracle
12.2.1.3.0
weblogic_serverby oracle
12.2.1.4.0
weblogic_serverby oracle
14.1.1.0.0
Updated Aug 21, 2026View on NVD →
Detail

Oracle WebLogic Server is a key component of Oracle's cloud platform, often utilized by enterprises for building and deploying enterprise Java EE applications. It is widely used for integrating software solutions and providing internet applications for both internal and external corporate usages. Organizations utilize it for handling transactions, security protocols, and facilitating the crucial operational processes of their database systems. Its robust infrastructure supports large-scale data processing and enables reliable communication across distributed networks. The server is commonly deployed in industries such as finance, healthcare, and technology where critical backend services require high reliability and security protocols. Overall, it is valued for its scalability, flexibility, and comprehensive set of tools available for developers.

Remote Code Execution (RCE) is a critical security vulnerability that allows an attacker to execute arbitrary code on a vulnerable server. In the context of Oracle WebLogic Server, this vulnerability specifically arises due to insecure deserialization in certain WebLogic versions, which can be exploited over the network. The attacker does not need credentials to exploit this vulnerability, making it particularly dangerous as it can be triggered remotely. Successful exploitation enables the attacker to execute commands or inject malicious payloads directly on the server. This type of vulnerability often leads to full system compromise, giving the attacker high-level control over the system. Therefore, it poses a significant threat and requires prompt action from administrators to mitigate the risk.

The vulnerability in WebLogic Server stems from deserialization processes wherein certain inputs are not properly sanitized, allowing malicious payloads to be executed. The vulnerable endpoints rely on protocols such as IIOP and T3, which facilitate remote connections and administrative actions on the server. Exploitation involves crafting specific input bytes that bypass the traditional security checks within the serialization process. The flaw lies in how serialized data is parsed; incorrect handling can execute arbitrary shell commands supplied by the attacker. Network settings influence the success rate of this exploit, often observed on ports such as 7001 where WebLogic operates default services. Attackers often leverage automated scripts to exploit this vulnerability, enabling swift execution of unauthorized commands and scripts.

When this vulnerability is exploited, potential effects include unauthorized access to sensitive data, disruption of services, and ultimately, complete loss of control over the server. Malicious actors could retrieve confidential database records or inject malware to propagate within the internal network. Data breaches may lead to financial losses and damage to the organization's reputation, especially if customer data is involved. Additionally, exploitation could provide attackers the means to install backdoors, allowing further persistent access even after initial fixes are applied. Prolonged exploitation of this vulnerability can lead to significant operational disruptions and put compliance with industry standards at risk. Organizations may face legal repercussions if adequate protective measures are not implemented post-discovery.

REFERENCES

Solution Advice
  • Apply the latest security patches provided by Oracle to the affected versions immediately.
  • Restrict network access to trusted sources and networks to prevent unauthorized exploitation.
  • Implement network segmentation to limit exposure of vulnerable endpoints.
  • Regularly audit and monitor WebLogic Server instances for unusual activity.
  • Consider implementing application firewall rules to detect and block malicious deserialization activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-14644 Scanner - Remote Code Execution (RCE) vulnerability in Oracle WebLogic Server | S4E