LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-14750: Oracle WebLogic Server Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-14750 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.

CVE-2020-14750 is a remote code execution vulnerability in Oracle WebLogic Server. An unauthenticated attacker can abuse it to run code on the affected system. It is related to CVE-2020-14882. Because WebLogic often sits on internal application tiers and can be reachable from broader networks, successful exploitation can give an attacker a foothold for further movement or data access. Public detail on the exact weakness class is limited; confirm all version and configuration specifics against the vendor advisory.

How it works

Oracle and CISA describe this as an unspecified vulnerability in Oracle WebLogic Server that allows an unauthenticated attacker to achieve remote code execution. The CWE is not specified in the provided facts. In general terms for this product class, such flaws typically involve how the server handles certain requests or console/management paths so that crafted input reaches a component that interprets or executes it with the privileges of the WebLogic process.

An attacker who can reach the vulnerable service over the network sends requests that trigger the flaw and cause the server to run attacker-controlled code. No further exploit mechanics, payloads, or preconditions are given in the available facts; treat any public proof-of-concept material with caution and validate behavior only in controlled lab environments against the vendor’s description. Because the attack does not require authentication, exposure of the affected interface materially increases risk.

Am I affected? How to find it in your systems

Oracle WebLogic Server is commonly deployed as the application server for Java EE workloads—customer portals, internal business apps, middleware, and integration tiers. It may run on dedicated hosts, VMs, or containers, sometimes behind load balancers or reverse proxies.

How to remediate

Patch first. Apply the updates Oracle published for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”). Confirm the exact patch identifiers and supported versions in the official Oracle advisory rather than relying on third-party summaries.

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls appropriate to an unauthenticated RCE on an application server:

Schedule the official patch as soon as possible; compensating controls do not remove the underlying flaw.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities on application servers can lead to unauthorized access, persistence, and data theft. Known ransomware use is not documented for this CVE in the provided facts, but that does not rule out other post-exploitation activity. If you have reason to believe systems were compromised, follow your incident response process: isolate affected hosts, preserve logs and memory where appropriate, rotate credentials and secrets that the WebLogic process could access, and assess downstream data stores. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · WebLogic Server
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities