HomeSecurityWebLogic RCE flaw still being exploited

WebLogic RCE flaw still being exploited

WebLogic

The recently patched CVE-2020-2883 bug, which affected multiple versions of Oracle WebLogic Server, continues to be a target for malicious actors, according to the company.

The bug in question was patched by Oracle as part of the April 2020 Critical Patch Update, which fixed more than 405 vulnerabilities in addition to the reported bug.

About the error

The flaw in Oracle WebLogic allows hackers to execute arbitrary code on affected versions of the server. The vulnerability is due to Oracle's proprietary T3 protocol.

An attacker could exploit the vulnerability to execute arbitrary code.

A security researcher claimed to have created a proof-of-concept for exploiting the vulnerability, which he has published on GitHub.

The published exploit covers the following vulnerabilities: CVE-2020-2546, CVE-2020-2915, CVE-2020-2801, CVE-2020-2798, CVE-2020-2883, CVE-2020-2884, CVE-2020-2950.

By exploiting the vulnerability in WebLogic, malicious actors can gain access to corporate networks and deploy malware.

Oracle recommends that its users immediately apply the April 2020 Critical Patch Update, which covers 405 new security updates.

WebLogic Server flaws are nothing new for the company. Other vulnerabilities in Oracle WebLogic have been exploited in the past to deploy ransomware and crypto miners.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS