Article 59SFR Hackers are on the Hunt for Oracle Servers Vulnerable to Potent Exploit

Hackers are on the Hunt for Oracle Servers Vulnerable to Potent Exploit

by
Fnord666
from SoylentNews on (#59SFR)

upstart writes in with an IRC submission:

Hackers are on the hunt for Oracle servers vulnerable to potent exploit:

Hackers are scanning the Internet for machines that have yet to patch a recently disclosed flaw that force Oracle's WebLogic server to execute malicious code, a researcher warned Wednesday night.

Johannes Ullrich, dean of research at the SANS Technology Institute, said his organization's honeypots had detected Internetwide scans that probe for vulnerable servers. CVE-2020-14882[*], as the vulnerability is tracked, has a severity rating of 9.8 out of 10 on the CVSS scale. Oracle's October advisory accompanying a patch said exploits are low in complexity and require low privileges and no user interaction.

"At this point, we are seeing the scans slow down a bit," Ullrich wrote in a post. "But they have reached 'saturation' meaning that all IPv4 addresses have been scanned for this vulnerability. If you find a vulnerable server in your network: Assume it has been compromised."

[...] Vulnerable versions of WebLogic include 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Oracle credited voidfyoo of Chaitin Security Research Lab with its discovery.

[*] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14882.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments