
The recently patched CVE-2020-2883 bug, which affected multiple versions of Oracle WebLogic Server, continues to be a target for malicious actors, according to the company.
The bug in question was patched by Oracle as part of the April 2020 Critical Patch Update, which fixed more than 405 vulnerabilities in addition to the reported bug.
About the error
The flaw in Oracle WebLogic allows hackers to execute arbitrary code on affected versions of the server. The vulnerability is due to Oracle's proprietary T3 protocol.
An attacker could exploit the vulnerability to execute arbitrary code.
A security researcher claimed to have created a proof-of-concept for exploiting the vulnerability, which he has published on GitHub.
The published exploit covers the following vulnerabilities: CVE-2020-2546, CVE-2020-2915, CVE-2020-2801, CVE-2020-2798, CVE-2020-2883, CVE-2020-2884, CVE-2020-2950.
By exploiting the vulnerability in WebLogic, malicious actors can gain access to corporate networks and deploy malware.
Oracle recommends that its users immediately apply the April 2020 Critical Patch Update, which covers 405 new security updates.
WebLogic Server flaws are nothing new for the company. Other vulnerabilities in Oracle WebLogic have been exploited in the past to deploy ransomware and crypto miners.
