CVE-2020-14882

CRITICAL9.8Published on October 21, 2020

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Nov 3, 2021
  • US federal agencies must remediate it by May 3, 2022 (BOD 22-01)
  • First attack observed 11 days after disclosure
  • Confirmed by sensors, not only by reports

Apply updates per vendor instructions.

Source: CISA KEV · Aug 24, 2026 Aug 22, 2026 Aug 21, 2026 Aug 20, 2026 Aug 16, 2026 Aug 15, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendorsoracle

Affected products

VendorsProdottoVersioni
oracleweblogic server10.3.6.0.0

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database