CVE-2020-2551
published 2020-01-15CVE-2020-2551: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2023-12-07
Exploited in the wild
EPSS
93.17%
99.8th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert tcp $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (10.3.6)"; flow:established,to_client; content:"HELO|3a|10.3.6"; startswith; fast_pattern; classtype:policy-violation; sid:2030131; rev:3; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07;)
snort
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Oracle WebLogic CVE-2020-2551 Scanning"; flow:established,to_server; content:"|47 49 4f 50 01 02 00 03 00 00 00 17 00 00 00 02 00 00 00 00 00 00 00 0b 4e 61 6d 65 53 65 72 76 69 63 65|"; startswith; fast_pattern; reference:url,www.rapid7.com/db/vulnerabilities/oracle-weblogic-cve-2020-2551; reference:url,github.com/hktalent/CVE-2020-2551/blob/master/CVE-2020-2551.py; classtype:attempted-admin; sid:2030128; rev:1; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_05_08;)
bytes
47 49 4f 50 01 02 00 03 00 00 00 17 00 00 00 02 00 00 00 00 00 00 00 0b 4e 61 6d 65 53 65 72 76 69 63 65
bytes
HELO:10.3.6
- →Exploit traffic uses the GIOP/IIOP protocol; scan detection triggers on a GIOP request frame starting with bytes 47 49 4f 50 ("GIOP") followed by a NameService lookup payload directed at WebLogic servers.
- →Vulnerable WebLogic servers can be identified by their T3 protocol banner response beginning with 'HELO:10.3.6' (or other affected version strings); monitor outbound T3 responses from servers for these version strings.
- →Nuclei template fingerprints vulnerable WebLogic instances by fetching /console/login/LoginForm.jsp and matching version strings (10.3.6.0, 12.1.3.0, 12.2.1.3, 12.2.1.4) in the response body alongside the string 'WebLogic'.
- →Shodan/FOFA queries can identify exposed WebLogic instances: search for http.title:"oracle peoplesoft sign-in" or product:"oracle weblogic" to find potentially vulnerable internet-facing targets.
- →The vulnerability is exploitable over the IIOP protocol (not HTTP); ensure IIOP ports are blocked at the perimeter for unauthenticated external access to WebLogic servers. ↗
- ·The Snort rule for scanning detection (sid:2030128) is classified 'confidence Medium' — it may produce false positives on legitimate GIOP/IIOP traffic to WebLogic servers; tune accordingly.
- ·The T3 banner detection rule (sid:2030131) is informational severity only — it identifies vulnerable version exposure, not active exploitation; use it for asset inventory rather than alerting on active attacks.
- ·The Nuclei HTTP-based detection template only confirms version exposure via the login page, not successful exploitation; a version match indicates a potentially vulnerable target, not a confirmed compromise.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85qx-3cmc-hcq4: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components)
ghsa_unreviewed·2022-05-24
CVE-2020-2551 [HIGH] GHSA-85qx-3cmc-hcq4: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle Fusion Middleware Unspecified Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-2551 [CRITICAL] Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
Affected: Oracle Fusion Middleware
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://blog.eclecticiq.com/chinese-threat-actor-used-modified-cobalt-strike-variant-to-attack-taiwanese-critical-infrastructure; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/09055246/Modern-Asian-APT-groups-TTPs_report_eng.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://media.kaspersky
CISA
Oracle Fusion Middleware Unspecified Vulnerability
cisa·2023-11-16·CVSS 9.8
CVE-2020-2551 [CRITICAL] Oracle Fusion Middleware Unspecified Vulnerability
Vulnerability: Oracle Fusion Middleware Unspecified Vulnerability
Affected: Oracle Fusion Middleware
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.oracle.com/security-alerts/cpujan2020.html; https://nvd.nist.gov/vuln/detail/CVE-2020-2551
Remediation Due Date: 2023-12-07
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: WLS Core Components — CVE-2020-2551
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2020-2551 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: WLS Core Components — CVE-2020-2551
Oracle Oracle Fusion Middleware Risk Matrix: WLS Core Components vulnerability
CVE: CVE-2020-2551
CVSS: 9.8
Protocol: IIOP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Suricata
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (10.3.6)
suricata·2020-05-08·CVSS 9.8
CVE-2020-2551 [CRITICAL] ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (10.3.6)
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (10.3.6)
Rule: alert tcp $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (10.3.6)"; flow:established,to_client; content:"HELO|3a|10.3.6"; startswith; fast_pattern; classtype:policy-violation; sid:2030131; rev:3; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07;)
Suricata
ET EXPLOIT Possible Oracle WebLogic CVE-2020-2551 Scanning
suricata·2020-05-08·CVSS 9.8
CVE-2020-2551 [CRITICAL] ET EXPLOIT Possible Oracle WebLogic CVE-2020-2551 Scanning
ET EXPLOIT Possible Oracle WebLogic CVE-2020-2551 Scanning
Rule: alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Oracle WebLogic CVE-2020-2551 Scanning"; flow:established,to_server; content:"|47 49 4f 50 01 02 00 03 00 00 00 17 00 00 00 02 00 00 00 00 00 00 00 0b 4e 61 6d 65 53 65 72 76 69 63 65|"; startswith; fast_pattern; reference:url,www.rapid7.com/db/vulnerabilities/oracle-weblogic-cve-2020-2551; reference:url,github.com/hktalent/CVE-2020-2551/blob/master/CVE-2020-2551.py; classtype:attempted-admin; sid:2030128; rev:1; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_0
Suricata
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.1.3)
suricata·2020-05-08·CVSS 9.8
CVE-2020-2551 [CRITICAL] ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.1.3)
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.1.3)
Rule: alert tcp $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.1.3)"; flow:established,to_client; content:"HELO|3a|12.1.3"; startswith; fast_pattern; classtype:policy-violation; sid:2030132; rev:3; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07;)
Suricata
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.2.1)
suricata·2020-05-08·CVSS 9.8
CVE-2020-2551 [CRITICAL] ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.2.1)
ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.2.1)
Rule: alert tcp $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"ET INFO Oracle T3 Response with CVE-2020-2551 Vulnerable Version (12.2.1)"; flow:established,to_client; content:"HELO|3a|12.2.1"; startswith; fast_pattern; classtype:policy-violation; sid:2030130; rev:3; metadata:attack_target Server, created_at 2020_05_08, cve CVE_2020_2551, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07;)
Nuclei
Oracle WebLogic Server - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-2551 [CRITICAL] Oracle WebLogic Server - Remote Code Execution
Oracle WebLogic Server - Remote Code Execution
Oracle WebLogic Server (Oracle Fusion Middleware (component: WLS Core Components) is susceptible to a remote code execution vulnerability. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 2.2.1.3.0 and 12.2.1.4.0. This easily exploitable vulnerability could allow unauthenticated attackers with network access via IIOP to compromise Oracle WebLogic Server.
Template:
id: CVE-2020-2551
info:
name: Oracle WebLogic Server - Remote Code Execution
author: dwisiswant0
severity: critical
description: |
Oracle WebLogic Server (Oracle Fusion Middleware (component: WLS Core Components) is susceptible to a remote code execution vulnerability. Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 2.2.1.3.0 and 12.2.1.4.0. This
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Tenable
CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
blogs_tenable·2026-03-20·CVSS 9.8
[CRITICAL] CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
CISA warns of actively exploited Windows, Sophos, and Oracle bugs
blogs_bleepingcomputer·2023-11-17·CVSS 9.8
[CRITICAL] CISA warns of actively exploited Windows, Sophos, and Oracle bugs
## CISA warns of actively exploited Windows, Sophos, and Oracle bugs
## Bill Toulas
The U.S. Cybersecurity & Infrastructure Security Agency has added to its catalog of known exploited vulnerabilities (KEV) three security issues that affect Microsoft devices, a Sophos product, and an enterprise solution from Oracle.
The KEV catalog contains flaws confirmed to be exploited by hackers in attacks and serves as a repository for vulnerabilities that companies all over should treat with priority.
The agency is urging federal agencies to apply available security updates for the three issues before December 7. The three vulnerabilities are tracked as follows:
CVE-2023-36584 – "Mark of the Web" (MotW) security feature bypass on Microsoft Windows.
CVE-2023-1671 – Command injection vulnerability
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2020-01-15
Published
2023-11-16
Added to CISA KEV
Exploited in the wild