News: 1604412730

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Oracle patches severe flaw in WebLogic Server that could be exploited 'without the need for a username and password'

(2020/11/03)


Oracle has released an emergency patch after a security vulnerability was revealed in its WebLogic middleware last week.

The [1]security alert addresses CVE-2020-14750, a remote code execution vulnerability in Oracle WebLogic Server.

"This vulnerability is related to CVE-2020-14882, which was addressed in the October 2020 Critical Patch Update. It is remotely exploitable without authentication, i.e. may be exploited over a network without the need for a username and password," Oracle said in a security alert.

"Due to the severity of this vulnerability and the publication of exploit code on various sites, Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible."

If you haven't patched WebLogic server console flaws in the last eight days 'assume it has been compromised' [2]READ MORE

Big Red said the patch should be applied to Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.

The patch is designed to address the flaw revealed last week by Johannes Ullrich, dean of research at the SANS Technology Institute. [3]He spotted a massive spike in traffic on research "honeypot" systems as somebody tried to identify public-facing WebLogic servers that weren't patched against [4]CVE-2020-14882 . The flaw, with a CVSS score of 9.8, is an "easily exploitable vulnerability" in the application's console that can be targeted over HTTP without user interaction to execute code remotely.

"If you find a vulnerable server in your network, assume it has been compromised," Ullrich said.

Martin Biggs, vice president and general manager with Oracle and SAP support specialist Spinnaker Support, said the attack exploited authentication functions that were "not originally coded to a high standard, allowing a double encoding attack vulnerability".

However, the problem was only likely to apply to those taking a high-risk approach to middleware architecture, he added.

"It affects the Weblogic server where the admin console is on the open internet which is extremely bad practice. [If you did that] you'd expose managed servers, not the admin server on the open internet."

He advised users not to allow WebLogic Console access via open internet and to use a proxy server as a gateway between WLS server and the internet, configuring WebLogic Connection filters to accept connections from trusted hosts only.

Still, it will be an embarrassment for Oracle to have to issue the patch after its mega quarterly update, [5]which issued 402 fixes . Whoops. Seems like you missed one, Larry. ®

Get our [6]Tech Resources



[1] https://www.oracle.com/security-alerts/alert-cve-2020-14750.html

[2] https://www.theregister.com/2020/10/29/weblogic_exploit_attack/

[3] https://www.theregister.com/2020/10/29/weblogic_exploit_attack/

[4] https://www.theregister.com/2020/10/29/weblogic_exploit_attack/

[5] https://www.theregister.com/2020/10/21/oracle_october_patches/

[6] https://whitepapers.theregister.com/

Curses!

Steve K

Just finished applying the October ones!

The shitty BSU utility takes 45 minutes to spin up to the stage where you can start applying patches and the JVM can take 10GB or more of RAM to do it (at least on 10.3.6.0 - still supported for Hyperion EPM).

Great....

Re: Curses!

RichardBarrell

FWIW, advice given for this specific RCE was roughly "if it's online and unpatched, assume it's already compromised" and that was a few days ago. I assume that you probably don't have the admin console exposed to the internet, though. If you did, you'd want to be planning to do more than just apply patches.

On a lighter note: wow, 10GB of RAM to apply patches is kind of impressive. I wonder what they must be doing with it? *Nice* binary patching utilities are supposed to normally only eat memory proportional to the sum of the old and new file sizes. There aren't any files bigger than about 4GB being patched, are there?

F

Sanctimonious Prick

Fuck Islam!

The Arkansas legislature passed a law that states that the Arkansas
River can rise no higher than to the Main Street bridge in Little Rock.