Critical Updates for WebLogic and Other Oracle Products – Oracle CPU April 2020

PUBLISHED:
21 April 2020

Critical Updates for WebLogic and Other Oracle Products - Oracle CPU April 2020

Oracle released April critical patch updates for multiple Oracle products that include 405 patches. Oracle revealed 286 of those vulnerabilities are remotely exploitable across nearly two dozen product lines. Impacted with multiple critical flaws, rated 9.8 CVSS in severity, are 13 key Oracle products including Oracle Financial Services Applications, Oracle MySQL, Oracle Retail Applications and Oracle WebLogic Server, according to the Oracle April Critical Patch Update Pre-Release Announcement.

Important note Oracle released a critical remote code execution flaws in Oracle WebLogic Server (CVE-2020-2801, CVE-2020-2883, CVE-2020-2884, etc). Most of the vulnerabilities are related to the T3 protocol and XML deserialization and rated 9.8 CVSS in severity. In the past TechCERT observed that Oracle T3 deserialization security flaws were widely used for delivering ransomware and other malware to Sri Lankan and South Asian region organizations. Although there are no publicly available exploits, Oracle states that there are exploit attempts to exploit the vulnerabilities. It is only a matter of time to develop exploits by attackers.

Solution

TechCERT strongly recommends using on actively-supported versions and apply Critical Patch Update security patches without delay for Oracle Products.

TechCERT recommends applying patches in the following manner.

  • Give the priority to the external-facing components
  • Make a plan to apply critical patches first
  • Apply the patches timely without delay

Additionally, TechCERT strongly suggests administrators, to go through Oracle Critical Patch Update Advisory – April 2020.

More Information

Oracle Critical Patch Update Advisory – April 2020: https://www.oracle.com/security-alerts/cpuapr2020.html

16 April 2024 [NO.TCSA : 20240416-1-1-P]

Critical Command Injection Vulnerability Found in Palo Alto Networks GlobalProtect

READ MORE READ MORE
9 February 2024 [NO.TCSA : 20240209-1-1-P]

Critical Remote Code Execution Vulnerability Found in FortiOS SSL VPN

READ MORE READ MORE
13 July 2023 [NO.TCSA : 20230713-1-1-P]

Fortinet Patches Critical Remote Code Execution Vulnerability in FortiOS/FortiProxy

READ MORE READ MORE
Read More BACK TO THREAT BULLETIN