Oracle is releasing an additional patch to fix a bug for the second time after publishing proof-of-concept exploit code.

Oracle on Sunday released a rare, out-of-the-box security update to address an incomplete patch for a recently disclosed vulnerability in Oracle WebLogic servers that is currently being actively exploited in real-world attacks.
The new patch (called CVE-2020-14750) adds additional fixes to an earlier bug (CVE-2020-14882), which was originally fixed with Oracle's standard October 2020 quarterly security updates.
CVE-2020-14882 is a critical vulnerability that allows attackers to execute malicious code on an Oracle WebLogic server with elevated privileges before server authentication has begun.
To exploit CVE-2020-14882, an attacker only needs to send an HTTP GET request to the WebLogic server management console
Since the exploit is trivial, the proof-of-concept (PoC) exploit code was made public within days of Oracle's initial patch.
But these POCs were quickly adopted by various threat groups, and last week, SANS ISC reported attacks against WebLogic honeypots.
But even the patched systems were not considered secure.
According to Adam Boileau, principal security consultant at Insomnia Sec, the original patch for CVE-2020-14882 could be bypassed if attackers changed one character in the standard POC exploit.
The recent attacks and the bypassing of the initial patch led Oracle to issue a second set of updates on Sunday, in a rare unscheduled security update.
It is recommended that companies running WebLogic servers install the additional CVE-2020-14750 patch to protect against both the original CVE-2020-14882 exploit and bypass .
According to security firm Spyse, more than 3,300 WebLogic servers are currently exposed to the internet and are considered vulnerable to the original vulnerability CVE-2020-14882.
