CVE-2020-2883
published 2020-04-15CVE-2020-2883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2025-01-28
Exploited in the wild
EPSS
94.93%
99.9th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts via the T3/T3S protocol targeting Oracle WebLogic Server deserialization; Check Point IPS signature is available for this CVE. ↗
- →Monitor for deserialization gadget chain invocations involving ChainedExtractor.extract(), ExtractorComparator, AbstractExtractor, and MultiExtractor classes in Oracle Coherence library traffic. ↗
- →Monitor for AMF (Action Message Format) deserialization traffic to BIRemotingServlet on TCP port 7780 on Oracle Business Intelligence servers; arbitrary objects can be reconstructed via readComplexObject(). ↗
- →Alert on use of ysoserial gadget chains (BeanShell1, Jython1, CommonsCollections2, CommonsBeanutils1, CommonsCollections4, Groovy1) and its JRMP listener against WebLogic T3 or HTTP endpoints. ↗
- →Restrict or monitor T3/T3S protocol traffic to Oracle WebLogic Server as an interim detection/mitigation measure. ↗
- →Watch for UnicastRef object reconstruction in deserialized traffic, which triggers the server-side distributed garbage collector for a remote object and enables response with an arbitrary serialized payload. ↗
- ·CVE-2020-2883 is a bypass of the incomplete patch for CVE-2020-2555; systems patched only for CVE-2020-2555 remain vulnerable. ↗
- ·The vulnerability resides in the Oracle Coherence library; any application with Coherence in its code path where there is a path to deserialization is also vulnerable, not just WebLogic Server itself (e.g., Oracle Business Intelligence). ↗
- ·Affected WebLogic versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0; exploitation confirmed on Linux (12.2.1.4), Windows confirmation was pending at time of report. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-09-18·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateSeptember 18, 2025
Alert CodeICSA-25-261-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerability: Deserialization of Untrusted Data
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow attackers to compromise Oracle WebLogic Server, resulting in potential impacts on confidentiality, integrity, and availability.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports that the following products are affected:
- Service Suite: Versions prior to 9.6.0.4
CISA
Oracle WebLogic Server Unspecified Vulnerability
cisa·2025-01-07·CVSS 9.8
CVE-2020-2883 [CRITICAL] Oracle WebLogic Server Unspecified Vulnerability
Vulnerability: Oracle WebLogic Server Unspecified Vulnerability
Affected: Oracle WebLogic Server
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.oracle.com/security-alerts/cpuapr2020.html ; https://nvd.nist.gov/vuln/detail/CVE-2020-2883
Remediation Due Date: 2025-01-28
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2020-2883
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2020-2883 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Core — CVE-2020-2883
Oracle Oracle Fusion Middleware Risk Matrix: Core vulnerability
CVE: CVE-2020-2883
CVSS: 9.8
Protocol: IIOP, T3
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
GHSA
GHSA-9x8q-p3qp-r24w: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
ghsa_unreviewed·2022-05-24
CVE-2020-2883 [HIGH] GHSA-9x8q-p3qp-r24w: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle WebLogic Server Unspecified Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-2883 [CRITICAL] Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Affected: Oracle WebLogic Server
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://blogs.oracle.com/security/post/customers-should-apply-the-april-2020-critical-patch-update-without-delay; https://cisa.gov/news-events/alerts/2020/05/01/unpatched-oracle-weblogic-servers-vulnerable-cve-2020-2883; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/resources/research-reports/global-cybersecurity-repor
No detection rules found.
Metasploit
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
metasploit
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
There exists a Java object deserialization vulnerability in multiple versions of WebLogic. Unauthenticated remote code execution can be achieved by sending a serialized `BadAttributeValueExpException` object over the T3 protocol to vulnerable versions of WebLogic. Leveraging an `ExtractorComparator` enables the ability to trigger `method.invoke()`, which will execute arbitrary code.
Nuclei
Oracle WebLogic Server - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-2883 [CRITICAL] Oracle WebLogic Server - Remote Code Execution
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Template:
id: CVE-2020-2883
info:
name: Oracle WebLogic Server - Remote Code Execution
author: daffainfo
severity: critical
description: |
Vulnerability in the Oracle WebLogic Server product
Bleepingcomputer
CISA warns of critical Oracle, Mitel flaws exploited in attacks
blogs_bleepingcomputer·2025-01-07·CVSS 9.8
CVE-2024-41713 [CRITICAL] CISA warns of critical Oracle, Mitel flaws exploited in attacks
## CISA warns of critical Oracle, Mitel flaws exploited in attacks
## Sergiu Gatlan
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
The cybersecurity agency added a critical path traversal vulnerability ( CVE-2024-41713 ) found in the NuPoint Unified Messaging (NPM) component Mitel's MiCollab unified communications platform to its Known Exploited Vulnerabilities Catalog .
This security bug allows attackers to perform unauthorized administrative actions and access user and network information.
"A successful exploit of this vulnerability could allow an attacker to gain unauthorized access, with potential impacts to the confidentiality, integrity, an
Tenable
CVE-2020-14882: Oracle WebLogic Remote Code Execution Vulnerability Exploited in the Wild
blogs_tenable·2020-10-29·CVSS 9.8
[CRITICAL] CVE-2020-14882: Oracle WebLogic Remote Code Execution Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update for October 2020 Addresses 402 Security Updates
blogs_tenable·2020-10-21
Oracle Critical Patch Update for October 2020 Addresses 402 Security Updates
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update for July 2020 Tops Previous Record with 443 Security Updates
blogs_tenable·2020-07-15
Oracle Critical Patch Update for July 2020 Tops Previous Record with 443 Security Updates
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2020-2883: Oracle WebLogic Deserialization Vulnerability Exploited in the Wild
blogs_tenable·2020-05-13·CVSS 9.8
[CRITICAL] CVE-2020-2883: Oracle WebLogic Deserialization Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Oracle WebLogic Vulnerability
blogs_trendmicro·2020-05-11·CVSS 9.8
CVE-2020-2555 [CRITICAL] Oracle WebLogic Vulnerability
## Details on the Oracle WebLogic Vulnerability Being Exploited in the Wild
Learn about one major Oracle WebLogic vulnerability being exploited in the wild.
By: Zero Day Initiative May 11, 2020 Read time: ( words)
Save to Folio
Earlier this year, I blogged about a deserialization vulnerability in the Oracle WebLogic Server. This was patched by Oracle and assigned CVE-2020-2555. However, researcher Quynh Le of VNPT ISC submitted a bug to the ZDI that showed how the patch could be bypassed. This bug, labeled CVE-2020-2883 , is now being reported by Oracle as being used in active attacks. In this blog post, we will go through the details of this recently-patched vulnerability.
Any ability to invoke ChainedExtractor.extract() will still result in remote code execution. The report from Quy
Trendmicro
Oracle WebLogic Vulnerability
blogs_trendmicro·2020-05-11·CVSS 9.8
CVE-2020-2555 [CRITICAL] Oracle WebLogic Vulnerability
# Details on the Oracle WebLogic Vulnerability Being Exploited in the Wild
Learn about one major Oracle WebLogic vulnerability being exploited in the wild.
By: Zero Day Initiative
2020/05/11
Read time: ( words)
Save to Folio
Earlier this year, I blogged about a deserialization vulnerability in the Oracle WebLogic Server. This was patched by Oracle and assigned CVE-2020-2555. However, researcher Quynh Le of VNPT ISC submitted a bug to the ZDI that showed how the patch could be bypassed. This bug, labeled CVE-2020-2883, is now being reported by Oracle as being used in active attacks. In this blog post, we will go through the details of this recently-patched vulnerability.
Patch Bypass
The original patch for CVE-2020-2555 did not address the lower portion of the following gadget chain:
Trendmicro
Oracle WebLogic Vulnerability
blogs_trendmicro·2020-05-11·CVSS 9.8
CVE-2020-2555 [CRITICAL] Oracle WebLogic Vulnerability
## Details on the Oracle WebLogic Vulnerability Being Exploited in the Wild
Learn about one major Oracle WebLogic vulnerability being exploited in the wild.
By: Zero Day Initiative 2020/05/11 Read time: ( words)
Save to Folio
Earlier this year, I blogged about a deserialization vulnerability in the Oracle WebLogic Server. This was patched by Oracle and assigned CVE-2020-2555. However, researcher Quynh Le of VNPT ISC submitted a bug to the ZDI that showed how the patch could be bypassed. This bug, labeled CVE-2020-2883 , is now being reported by Oracle as being used in active attacks. In this blog post, we will go through the details of this recently-patched vulnerability.
Any ability to invoke ChainedExtractor.extract() will still result in remote code execution. The report from Quynh
Checkpoint
11th May – Threat Intelligence Bulletin
blogs_checkpoint·2020-05-11
CVE-2020-8899 11th May – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th May – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 11th May 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research have discovered an ongoing cyber espionage operation against government entities in the Asia Pacific (APAC) region. The operation is attributed to the Naikon APT group, using a backdoor dubbed Aria-body to take control of the victims’ networks. One of the attack vectors was infecting a foreign embassy
Greynoiseio
NoiseLetter January 2025
blogs_greynoiseio
NoiseLetter January 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/157950/WebLogic-Server-Deserialization-Remote-Code-Execution.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-504/https://www.zerodayinitiative.com/advisories/ZDI-20-570/http://packetstormsecurity.com/files/157950/WebLogic-Server-Deserialization-Remote-Code-Execution.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-20-504/https://www.zerodayinitiative.com/advisories/ZDI-20-570/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-2883
2020-04-15
Published
2025-01-07
Added to CISA KEV
Exploited in the wild