EXPOSURES › CVE-2020-14883
CVE-2020-14883
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability.
Oracle WebLogic Server's Console component had an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability. DIB organizations must treat WebLogic as a high-risk asset requiring strict network segmentation, continuous patching via Oracle's Critical Patch Updates, and rigorous vulnerability management. Failure to patch known WebLogic vulnerabilities can lead to severe security incidents and compliance failures.
Shame score — The vulnerability was actively exploited in the wild, indicating a failure to patch known issues and a poor security posture for a widely deployed enterprise application server.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentiality, integrity, and availability."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |