EXPOSURES › CVE-2020-14750
CVE-2020-14750
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild.
An unauthenticated attacker could execute arbitrary code on Oracle WebLogic Server via a known vulnerability, which was actively exploited in the wild. This failure highlights the severe risk of relying on enterprise software with a history of critical flaws without rigorous patching and network segmentation. DIB organizations must treat WebLogic as a high-risk asset requiring continuous vulnerability management and strict isolation to prevent similar exposures.
Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and part of WebLogic's recurring pattern of critical RCE flaws, representing a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
"Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |