CVE-2020-2883 - Oracle WebLogic Server Unspecified Vulnerability
Project:Oracle
Product:WebLogic Server
Date Added:2025-01-07Due Date:2025-01-28
Vulnerability Name
Oracle WebLogic Server Unspecified Vulnerability
Description
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://www.oracle.com/security-alerts/cpuapr2020.html
https://nvd.nist.gov/vuln/detail/CVE-2020-2883
Related News Articles
Oracle Releases January 2025 Patch to Address 318 Flaws Across Major ProductsJanuary 22, 2025
Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackersJanuary 8, 2025
CISA Flags Critical Flaws in Mitel and Oracle Systems Amid Active ExploitationJanuary 8, 2025
CISA warns of critical Oracle, Mitel flaws exploited in attacksJanuary 8, 2025