Security News > 2020 > November > Oracle Issues Out-of-Band Update for Critical Vulnerability Exploited in Attacks

Oracle Issues Out-of-Band Update for Critical Vulnerability Exploited in Attacks
2020-11-02 21:05

Oracle has released an out-of-band security alert for a critical remote code execution vulnerability affecting WebLogic Server.

"This Security Alert addresses CVE-2020-14750, a remote code execution vulnerability in Oracle WebLogic Server. [] It is remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password," Oracle notes in its advisory.

"The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and execute arbitrary code on the target system. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system," Czech vulnerability intelligence company Cybersecurity Help says.

In its advisory, Oracle credited 20 researchers/organizations for reporting the vulnerability.

"Due to the severity of this vulnerability and the publication of exploit code on various sites, Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible," Oracle notes.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/6NLX3KRidtE/oracle-warns-weblogic-flaw-related-exploited-vulnerability

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2020-14750 Unspecified vulnerability in Oracle Fusion Middleware
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).
network
low complexity
oracle
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Oracle 781 388 3148 2078 432 6046