According to new reports from security, cybercriminals have begun exploiting a critical vulnerability in Oracle WebLogic server. The vulnerability is known as CVE-2020-14882.

Hackers are scanning the Internet for servers running versions of Oracle WebLogic vulnerable to this flaw.
CVE-2020-14882, discovered by security researcher Voidfyoo from Chaitin Security Research Lab, can be exploited by unauthorized users. Attackers can take control of a system by sending a simple HTTP GET request.
The vulnerability has been rated 9.8 out of 10 on the vulnerability severity scale. However, Oracle has already addressed this bug with the Critical Patch Update (CPU) released this month.
The affected Oracle WebLogic Server versions are: 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.
Security researchers from the SANS Technology Institute created honeypots that allowed them to see a series of attacks exploiting this vulnerability. The attacks began shortly after the bug's exploit code was published.
Researchers observed that attacks targeting honeypots originated from the following IP addresses:
- 114.243.211.182 (China)
- 139.162.33.228 (USA)
- 185.225.19.240 (Moldova)
- 84.17.37.239 (Hong Kong)
According to SANS experts, the exploit used in the attacks appears to be based on the code published by researcher Jang.

"These exploit attempts are currently attempting to verify whether the system is vulnerable," researchers at the SANS Technology Institute said in a post.
The SANS Institute is warning Internet service providers that use the IP addresses involved in the attacks.
According to experts, a search on the Spyse enginefor vulnerable Oracle WebLogic servers returned at least 3,000 results.
Oracle WebLogic server administrators should immediately update systems to fix the CVE-2020-14882 vulnerability and stay secure.
Source: Security Affairs
