cbcvebase.
CVE-2020-2883
published 2020-04-15

CVE-2020-2883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2025-01-28
Exploited in the wild
EPSS
94.93%
99.9th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

8 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

portT3/T3S protocol port (default 7001)
port7780
processBIRemotingServlet
  • Detect exploitation attempts via the T3/T3S protocol targeting Oracle WebLogic Server deserialization; Check Point IPS signature is available for this CVE.
  • Monitor for deserialization gadget chain invocations involving ChainedExtractor.extract(), ExtractorComparator, AbstractExtractor, and MultiExtractor classes in Oracle Coherence library traffic.
  • Monitor for AMF (Action Message Format) deserialization traffic to BIRemotingServlet on TCP port 7780 on Oracle Business Intelligence servers; arbitrary objects can be reconstructed via readComplexObject().
  • Alert on use of ysoserial gadget chains (BeanShell1, Jython1, CommonsCollections2, CommonsBeanutils1, CommonsCollections4, Groovy1) and its JRMP listener against WebLogic T3 or HTTP endpoints.
  • Restrict or monitor T3/T3S protocol traffic to Oracle WebLogic Server as an interim detection/mitigation measure.
  • Watch for UnicastRef object reconstruction in deserialized traffic, which triggers the server-side distributed garbage collector for a remote object and enables response with an arbitrary serialized payload.
  • ·CVE-2020-2883 is a bypass of the incomplete patch for CVE-2020-2555; systems patched only for CVE-2020-2555 remain vulnerable.
  • ·The vulnerability resides in the Oracle Coherence library; any application with Coherence in its code path where there is a path to deserialization is also vulnerable, not just WebLogic Server itself (e.g., Oracle Business Intelligence).
  • ·Affected WebLogic versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0; exploitation confirmed on Linux (12.2.1.4), Windows confirmation was pending at time of report.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.