Skip to content
COOEY

EXPOSURES › CVE-2020-2551

CVE-2020-2551

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-11-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-2551 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Oracle Fusion Middleware WLS Core Components RCE vulnerability

An unspecified vulnerability in Oracle Fusion Middleware's WLS Core Components allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. This is a high-severity, actively exploited vulnerability that can lead to remote code execution, impacting organizations using this product.

Shame score — High-severity, actively exploited vulnerability with remote code execution capabilities, impacting critical systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized