Netskope Threat Labs

SERVER-WEBAPP Oracle WebLogic Server command injection attempt

IPS-NPA

4 SIDs: 56200, 56201, 56202, 56203

Detects an attempt to exploit CVE-2020-14882, a command injection flaw that can run operating system commands on the server in Oracle WebLogic Server. The flaws saw mass exploitation of internet-facing WebLogic servers, frequently followed by ransomware deployment.