
This election doc caught my eye. SQL injection in New York and Delaware Oracle Exploitation attempts in Delaware. Major Vulnerabilities: CVE-2020-14882: A critical remote code execution flaw in the WebLogic Server console with a maximum severity score of 9.8. CVE-2020-14750: An easily exploitable follow-up bug related to the same WebLogic console component that allowed full system takeover. CVE-2020-2883: Another remote code execution flaw tied to insecure Java object handling in WebLogic. ® Key Characteristics No Password Needed: Attackers did not need user accounts or credentials to break in; simple network HTTP requests were enough. Active Exploitation: Threat actors scanned the internet for exposed management consoles to run malicious
Post summary
The post details critical WebLogic RCE CVEs, confirms that threat actors are actively exploiting exposed consoles via simple HTTP requests, and provides technical details but no PoC or patch information.
