EXPOSURES › CVE-2020-2551
CVE-2020-2551
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Fusion Middleware WLS Core Components RCE vulnerability
An unspecified vulnerability in Oracle Fusion Middleware's WLS Core Components allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server. This is a high-severity, actively exploited vulnerability that can lead to remote code execution, impacting organizations using this product.
Shame score — High-severity, actively exploited vulnerability with remote code execution capabilities, impacting critical systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |