EXPOSURES › CVE-2020-14882
CVE-2020-14882
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild.
Oracle WebLogic Server contains a remote code execution vulnerability (CVE-2020-14882) that was assessed to allow remote code execution and was added to CISA's KEV catalog, indicating active exploitation. DIB organizations must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching via Oracle's Critical Patch Updates, and rigorous vulnerability management to prevent compromise. The vendor's historically poor security posture and recurring critical vulnerabilities make this failure highly avoidable through diligent patch management.
Shame score — A critical remote code execution flaw in a widely deployed enterprise server was actively exploited in the wild, demonstrating severe negligence in patch management and a historically poor security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |