'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-14882,CVE-2020-14883: WebLogic Unauthorized bypass Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2020-14882 CVE-2020-14883
| Descripiton:
|
Oracle WebLogic Server is an application service middleware from Oracle Corporation of the United States that is suitable for cloud environments and traditional environments. It provides a modern lightweight development platform that supports the entire life cycle management of applications from development to production, and simplifies Application deployment and management. Oracle WebLogic Server's multi-version Oracle Fusion Middleware has a security vulnerability, which allows unauthenticated attackers to access the network through HTTP, thereby destroying Oracle WebLogic Server. The affected products and versions are as follows: Version 10.3.6.0.0, version 12.1.3.0.0, version 12.2.1.3.0, version 12.2.1.4.0, version 14.1.1.0.0. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.