Skip to content
COOEY

EXPOSURES › CVE-2020-14882

CVE-2020-14882

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-14882 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Oracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild.

Oracle WebLogic Server contains a remote code execution vulnerability (CVE-2020-14882) that was assessed to allow remote code execution and was added to CISA's KEV catalog, indicating active exploitation. DIB organizations must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching via Oracle's Critical Patch Updates, and rigorous vulnerability management to prevent compromise. The vendor's historically poor security posture and recurring critical vulnerabilities make this failure highly avoidable through diligent patch management.

Shame score — A critical remote code execution flaw in a widely deployed enterprise server was actively exploited in the wild, demonstrating severe negligence in patch management and a historically poor security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Oracle faced severe fallout due to a critical remote code execution vulnerability in WebLogic Server, widely condemned by security researchers and the press for the risk it posed to enterprise environ
cooey ↗ severe-fallout -0.60
severe-fallout
"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750."
AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized