Netskope Threat Labs

SERVER-WEBAPP Oracle WebLogic Server remote code execution attempt

IPS-NPA

1 SID: 58562

Detects an attempt to exploit CVE-2020-14750, CVE-2020-14882, and CVE-2020-14883, a remote code execution flaw that can run code on the server in Oracle WebLogic Server. The flaws saw mass exploitation of internet-facing WebLogic servers, frequently followed by ransomware deployment.