Description
Oracle announced a critical patch update to address a vulnerability (CVE-2020-2551) found in its WebLogic Server that affects the product's WLS Core Components subcomponent due to unsafe deserialization of Java objects. An unauthenticated, remote attacker can exploit this vulnerability by crafting a Java object to execute arbitrary Java code in the context of the WebLogic server.
Remediation
Upgrade to the latest version of Oracle WebLogic Server. This issue was fixed in Oracle Critical Patch Update - October 2020. Or disable/restrict access to IIOP protocol
References
Oracle Critical Patch Update Advisory - January 2020
Unauthenticated Remote Code Execution in IIOP protocol via Malicious JNDI Lookup