CVE Tools

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

In plain language

AI Act now

CVE-2020-2551 is a serious WebLogic Server flaw where an attacker can take full control over the server from the network without logging in—small businesses using affected WebLogic versions should treat this as urgent and update or mitigate immediately.

Executive summary

Unauthenticated remote takeover is possible in Oracle WebLogic Server via an IIOP protocol handling flaw, allowing an attacker to seize full control without any login or user interaction.

If affected, business impact
Full application takeoverBusiness outage riskCustomer data exposureData tampering and loss

What to do now

  1. Check whether your organization runs Oracle WebLogic Server version 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, or 12.2.1.4.0.
  2. Confirm whether the IIOP interface/protocol is exposed and reachable from other networks (especially any public network path to the server).
  3. Apply the Oracle vendor mitigations from the Oracle CPU January 2020 security alert linked in the advisory (and follow any additional vendor steps for your exact version).
  4. If you can, upgrade WebLogic Server to a fixed/supported version that is not affected by CVE-2020-2551, following Oracle’s guidance for your maintenance line.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Oracle Corporation
commercial·USaka Oracle Corp., oracle
and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 16, 2023
Remediation due:Dec 7, 2023

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 2 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2020-2551 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows