
Oracle WebLogic Server users should update their systems immediately, as a new threat has emerged and is spreading an unknown ransomware variant, according to cyber researchers.
Oracle was forced to break its normal schedule to release a patch update on April 26. The vulnerability turns out to be quite serious.
The vulnerability allows attackers to remotely control hosts and execute malicious code. The flaw in Oracle WebLogic can be exploited over a Network without requiring a Username and Password.
Alert Logic states that an attacker, exploiting the vulnerability, could send a malicious HTTP request to execute commands remotely and without authorization. Oracle attributes the discovery of the bug to the Chinese Knownsec 404 Team and eight other Chinese cyber security researchers. The severity of the bug lies in the ease of execution for those seeking to exploit it.
Attacks exploiting the recently discovered Oracle WebLogic vulnerability include the delivery of a previously unseen ransomware variant called “Sodinokibi,” Cisco Talos researchers said in an analysis of the flaw on Tuesday.
The team also notes that patches released through the Security Alert program are only provided for product versions covered by Premier Support or Extended Support or Lifetime Support Policy.
