cbcvebase.
CVE-2020-14859
published 2020-10-21

CVE-2020-14859: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.80%
88.8th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

10 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-14859 is exploitable over IIOP and T3 protocols — monitor for unauthenticated inbound connections on WebLogic's default IIOP (port 3700) and T3 (port 7001/7002) listener ports from external/untrusted sources
  • Affected Oracle WebLogic Server versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0 — prioritize detection and patching on hosts running these specific versions
  • Successful exploitation results in full server takeover (C/I/A all HIGH) — treat any anomalous process spawning from WebLogic JVM processes (e.g., cmd.exe, /bin/sh, powershell) following T3/IIOP traffic as a high-confidence indicator of compromise
  • ·The vulnerability is exposed via both IIOP and T3 protocols; if either protocol listener is enabled and reachable from untrusted networks, the server is at risk. Restrict or disable T3/IIOP access at the network perimeter if not required.
  • ·No authentication is required to exploit this vulnerability — network-level access alone is sufficient. There is no compensating control short of blocking the protocols or applying the patch.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.