CVE-2020-2551
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
In plain language
AI Act nowCVE-2020-2551 is a serious WebLogic Server flaw where an attacker can take full control over the server from the network without logging in—small businesses using affected WebLogic versions should treat this as urgent and update or mitigate immediately.
Unauthenticated remote takeover is possible in Oracle WebLogic Server via an IIOP protocol handling flaw, allowing an attacker to seize full control without any login or user interaction.
What to do now
- Check whether your organization runs Oracle WebLogic Server version 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, or 12.2.1.4.0.
- Confirm whether the IIOP interface/protocol is exposed and reachable from other networks (especially any public network path to the server).
- Apply the Oracle vendor mitigations from the Oracle CPU January 2020 security alert linked in the advisory (and follow any additional vendor steps for your exact version).
- If you can, upgrade WebLogic Server to a fixed/supported version that is not affected by CVE-2020-2551, following Oracle’s guidance for your maintenance line.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-2551 and every CVE in our database. Create a free account — no credit card required.
Create Free Account