Vulnerability record · CVE-2020-14841 · published 21 October 2020
CVE-2020-14841: Oracle WebLogic Server IIOP flaw allows unauthenticated takeover
Oracle · Weblogic Server
Oracle WebLogic Server Core contains an easily exploitable vulnerability reachable over IIOP that lets an unauthenticated network attacker compromise the server. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0, and successful exploitation results in full takeover. The record does not specify the underlying weakness, as NVD classifies it as insufficient information.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction and full server takeover, plus a high EPSS score, makes this a top remediation priority despite the absence of KEV listing.
What it is
Oracle WebLogic Server Core contains an easily exploitable vulnerability reachable over IIOP that lets an unauthenticated network attacker compromise the server. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0, and successful exploitation results in full takeover. The record does not specify the underlying weakness, as NVD classifies it as insufficient information.
Impact
An attacker gains complete control of the WebLogic Server, with high impact to confidentiality, integrity and availability. That typically means code execution in the server's context and access to hosted applications and data.
Attack surface
Reachable over the network via IIOP; the CVSS vector shows no privileges required and no user interaction. Any exposed IIOP listener on an affected WebLogic instance is a candidate entry point.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.52 (99th percentile), indicating elevated likelihood of exploitation activity. References are vendor patch and ZDI advisories only, with no public exploit tag in the record.
What to do
- Apply the Oracle October 2020 CPU patch for WebLogic Server, or upgrade to a fixed release.
- If IIOP is not required, disable or block the IIOP/T3 protocols and restrict the listener to trusted networks.
- Segment WebLogic management and internal protocol ports behind firewalls; do not expose them to untrusted networks.
- Monitor Oracle advisories and ZDI references for updated guidance and re-check affected versions after patching.
Detection
- Alert on unexpected inbound connections to WebLogic IIOP/T3 ports from untrusted sources.
- Look for anomalous child processes or command execution spawned by the WebLogic JVM.
- Monitor for unusual outbound connections or file writes from WebLogic server processes.
- Review WebLogic logs for IIOP-related errors or unexpected deserialization activity around suspicious connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpuoct2020.html | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1274/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1276/ | Third Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuoct2020.html | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1274/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1276/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-14841 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14841), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.