Skip to content
COOEY

EXPOSURES › CVE-2020-14883

CVE-2020-14883

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-14883 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Oracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability.

Oracle WebLogic Server's Console component had an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability. DIB organizations must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching via Oracle's Critical Patch Updates, and rigorous vulnerability management. Failure to patch known WebLogic vulnerabilities can lead to severe security incidents and compliance failures.

Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch known issues and a poor security posture for a widely deployed enterprise application server.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Oracle faced severe fallout due to a high-impact unspecified vulnerability in WebLogic Server's Console component, exposing confidentiality, integrity, and availability risks.
cooey ↗ severe-fallout -0.60
Oracle faced severe fallout due to a high-impact unspecified vulnerability in WebLogic Server's Console component, exposing confidentiality, integrity, and availability risks.
"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentiality, integrity, and availability."
AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized