News: 1604010920

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

If you haven't patched WebLogic server console flaws in the last eight days 'assume it has been compromised'

(2020/10/29)


Last week Oracle released one of its mammoth quarterly patch dumps - with [1]402 fixes . Well, it turns out that if you missed one and you're running WebLogic 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0, you've probably already been tagged by hackers.

On Thursday Johannes Ullrich, Dean of Research at the SANS Technology Institute, [2]spotted a massive spike in traffic on research "honeypot" systems as somebody tried to identify public-facing WebLogic servers that weren't patched against [3]CVE-2020-14882 . The flaw, with a CVSS score of 9.8, is an "easily exploitable vulnerability" in the application's console that can be targeted over HTTP without user interaction to execute code remotely.

How much does Oracle love you? Thiiiis much: Latest patch bundle has 402 fixes [4]READ MORE

"At this point, we are seeing the scans slow down a bit," he explained. But they have reached "saturation," meaning that all IPv4 addresses have been scanned for this vulnerability. If you find a vulnerable server in your network: Assume it has been compromised."

Ullrich said that the exploit code for the Java EE application server code being used appears to be based on information [5]published on Wednesday by someone identified as Nguyen Jang. The post, in Vietnamese, described how to get full access to an unpatched WebLogic server with a single GET request and had a video you can see below:

[6]Youtube Video

All of the exploit attempts originates from four IP addresses, Ullrich said.

114.243.211.182: China Unicom.

139.162.33.228 : Linode (U.S.A.)

185.225.19.240 : MivoCloud (Moldova).

84.17.37.239 : DataCamp Ltd (Hong Kong).

"These exploit attempts are right now just verifying if the system is vulnerable," he said. "Our honeypots (up to now) do not return the "correct" response, and we have not seen follow-up requests yet."

It's possible that this was a simple scan to estimate the total number of vulnerable machines; investigations are ongoing. In the meantime, patch and check all vulnerable machines and get to work on the [7]other 401 fixes - who knows which one is next? ®

Get our [8]Tech Resources



[1] https://www.theregister.com/2020/10/21/oracle_october_patches/

[2] https://isc.sans.edu/diary/26734

[3] https://nvd.nist.gov/vuln/detail/CVE-2020-14882

[4] https://www.theregister.com/2020/10/21/oracle_october_patches/

[5] https://testbnull.medium.com/weblogic-rce-by-only-one-get-request-cve-2020-14882-analysis-6e4b09981dbf

[6] https://www.youtube.com/watch?v=JFVDOIL0YtA&feature=emb_logo.

[7] https://www.oracle.com/security-alerts/cpuoct2020traditional.html

[8] https://whitepapers.theregister.com/

I'd been hearing all sorts of gloom and doom predictions for Y2K, so I
thought I'd heed some of the advice that the experts have been giving:
Fill up the car's gas tank, stock up on canned goods, fill up the bathtub
with water, and so on.

I guess I wasn't fully awake when I completed my preparations late last
night. This morning I found the kitchen shelves soaked in gasoline, water
in the car's gas tank, and my bathtub filled with baked beans.
-- Dan Pearl in a message to rec.humor.funny