Hi,
Can someone please help me understand the below 2 vulnerabilities? I mean both seems to be same except that the mechanism used to exploit or hack WebLogic is different? Also, it said "....with network access..". Does this mean exploiter needs to get into network first before they can do anything on WebLogic, if the WebLogic is not internet facing? What if the WebLogic is shutdown and never needed to run?
CVE-2019-2725 Oracle WebLogic Server
CVE-2020-14882 Oracle WebLogic
Thanks in advance,
PM