CVE-2020-14882

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...

Basic Information

CVE State
PUBLISHED
Reserved Date
June 19, 2020
Published Date
October 21, 2020
Last Updated
September 26, 2024
Vendor
Oracle Corporation
Product
WebLogic Server
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2021-11-03 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2023-04-28 12:38:52 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2021-11-03 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

xMr110/CVE-2020-14882

Type: github • Created: 2024-02-04 09:36:09 UTC • Stars: 0

LucasPDiniz/CVE-2020-14882

Type: github • Created: 2023-11-09 04:31:26 UTC • Stars: 0

Takeover of Oracle WebLogic Server

Danny-LLi/CVE-2020-14882

Type: github • Created: 2023-07-17 07:59:01 UTC • Stars: 2

This script allows for remote code execution (RCE) on Oracle WebLogic Server

Root-Shells/CVE-2020-14882

Type: github • Created: 2023-04-28 12:38:52 UTC • Stars: 0

CVE-2020-14882 rewritten in PowerShell

N0Coriander/CVE-2020-14882-14883

Type: github • Created: 2021-07-03 02:02:42 UTC • Stars: 2

结合14882的未授权访问漏洞,通过14883可远程执行任意代码

qianniaoge/CVE-2020-14882_Exploit_Gui

Type: github • Created: 2021-05-25 08:59:45 UTC • Stars: 0

exploitblizzard/CVE-2020-14882-WebLogic

Type: github • Created: 2021-05-10 21:32:36 UTC • Stars: 3

Check YouTube - https://youtu.be/O0ZnLXRY5Wo

kk98kk0/CVE-2020-14882

Type: github • Created: 2021-03-31 07:49:06 UTC • Stars: 3

CVE-2020-14882部署冰蝎内存马

milo2012/CVE-2020-14882

Type: github • Created: 2021-02-25 12:57:08 UTC • Stars: 8

CVE-2020-14882

xfiftyone/CVE-2020-14882

Type: github • Created: 2020-11-12 11:27:39 UTC • Stars: 5

corelight/CVE-2020-14882-weblogicRCE

Type: github • Created: 2020-11-12 06:59:54 UTC • Stars: 7

Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

Ormicron/CVE-2020-14882-GUI-Test

Type: github • Created: 2020-11-11 06:52:32 UTC • Stars: 2

基于qt的图形化CVE-2020-14882漏洞回显测试工具.

murataydemir/CVE-2020-14882

Type: github • Created: 2020-11-09 13:02:43 UTC • Stars: 2

[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass

QmF0c3UK/CVE-2020-14882

Type: github • Created: 2020-11-09 08:03:44 UTC • Stars: 8

NS-Sp4ce/CVE-2020-14882

Type: github • Created: 2020-11-04 03:09:13 UTC • Stars: 21

CVE-2020-14882/14883/14750

GGyao/CVE-2020-14882_ALL

Type: github • Created: 2020-11-03 10:49:35 UTC • Stars: 145

CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。

GGyao/CVE-2020-14882_POC

Type: github • Created: 2020-10-31 01:43:54 UTC • Stars: 12

CVE-2020-14882批量验证工具。

alexfrancow/CVE-2020-14882

Type: github • Created: 2020-10-30 11:07:11 UTC • Stars: 0

XTeam-Wing/CVE-2020-14882

Type: github • Created: 2020-10-29 06:30:30 UTC • Stars: 17

CVE-2020-14882 Weblogic-Exp

s1kr10s/CVE-2020-14882

Type: github • Created: 2020-10-28 21:28:12 UTC • Stars: 29

CVE-2020–14882 by Jang

jas502n/CVE-2020-14882

Type: github • Created: 2020-10-28 11:43:37 UTC • Stars: 283

CVE-2020–14882、CVE-2020–14883