EXPOSURES › CVE-2020-14644
CVE-2020-14644
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.
This deserialization flaw allows attackers to execute arbitrary code on WebLogic instances without authentication via T3 or IIOP protocols, posing a severe risk to DIB organizations relying on Oracle Fusion Middleware. The vulnerability is actively exploited, requiring immediate patching and network segmentation to prevent unauthorized access to sensitive systems.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a failure in Oracle's timely patching and vendor security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |