Security News > 2020 > October > Oracle WebLogic Vulnerability Targeted One Week After Patching
A vulnerability patched one week ago by Oracle in its WebLogic Server product has already been targeted for exploitation.
The vulnerability can be exploited remotely and without authentication, allowing an attacker to execute arbitrary code.
The SANS Technology Institute reported on Thursday that its honeypots have recorded attempts to exploit this WebLogic vulnerability.
Oracle WebLogic Server vulnerabilities are often targeted by threat actors, including profit-driven cybercriminals and state-sponsored groups.
Shortly after the April 2020 CPU was released, Oracle warned customers that a critical WebLogic vulnerability, one that was disclosed to the vendor by multiple researchers, including Jang, had been exploited in the wild.