
Vulnerability
WebLogic is one of the main products of Oracle Corporation in the United States. A remote attacker can construct a special HTTP request, to take over the WebLogic Server Console without authentication, and execute arbitrary code, with low utilization threshold and great harm.
Impact
Remote and unauthorized attackers can directly execute arbitrary code on the server to obtain system permissions.
Affected versions
weblogic 10.3.6.0.0, 2.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Mitigation
We recommend you to refer and apply the patch released on the oracle official website: Oracle Critical Patch Update Advisory-October 2020(https://www.oracle.com/security-alerts/cpuoct2020traditional.html).
Summarize:
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days





