CVE-2020-2966: Medium severity oracle weblogic server vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2966?
CVE-2020-2966 has a CVSS score indicating a critical severity level due to its ability to be exploited by unauthenticated attackers.
How do I fix CVE-2020-2966?
To fix CVE-2020-2966, update your Oracle WebLogic Server to the latest patched version provided by Oracle.
What versions are affected by CVE-2020-2966?
CVE-2020-2966 affects Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0.
What types of attacks can be carried out using CVE-2020-2966?
CVE-2020-2966 allows unauthenticated remote attackers to compromise the server via HTTP requests.
Is authentication required to exploit CVE-2020-2966?
No, CVE-2020-2966 can be exploited without authentication, making it easier for attackers to compromise vulnerable systems.