CVE-2020-2883
Oracle Weblogic Server 10.3.6.0.0 … 12.2.1.4.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2020-2883 is a critical-severity an unspecified weakness vulnerability in Oracle Weblogic Server. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 0.1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2020-2883 is a vulnerability in the Core component of Oracle WebLogic Server within Oracle Fusion Middleware. It affects supported versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0. The flaw is reachable over the network through IIOP or T3 protocols and carries a CVSS 3.1 base score of 9.8 with full impacts to confidentiality, integrity, and availability.
An unauthenticated attacker with network access can exploit the issue to achieve remote takeover of the WebLogic Server instance. No user interaction or credentials are required, making the attack surface broad for any exposed server.
Oracle's April 2020 Critical Patch Update addresses the vulnerability, and separate Zero Day Initiative advisories (ZDI-20-504 and ZDI-20-570) provide additional technical detail on the flaw. Public exploit artifacts referencing deserialization remote code execution have also been posted to Packet Storm.
The combination of an unauthenticated network vector, critical severity, and readily available proof-of-concept material indicates the issue is of immediate concern for organizations running the listed WebLogic versions.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-22676
Vulnerability Data
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic…
more
Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CWE(s)
- KEV Date Added
- 07 January 2025
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.