CVE-2020-14882

critical

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

From the Tenable Blog

CVE-2020-14882: Oracle WebLogic Remote Code Execution Vulnerability Exploited in the Wild
CVE-2020-14882: Oracle WebLogic Remote Code Execution Vulnerability Exploited in the Wild

Published: 2020-10-29

A remote code execution vulnerability in Oracle WebLogic Server has been actively exploited in the wild just one week after a patch was released and one day after a proof of concept was published.Update October 30, 2020: The solutions section has been updated to reflect the disclosure of a potential bypass of the patch for CVE-2020-14882.Update November 2, 2020: The solutions section has been updated to reflect the release of a patch to address the potential bypass of the patch for CVE-2020-14482.

References

https://github.com/hyderpwn/weblogic

https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis

https://github.com/chengbochuan3/CVE-Web-Framework

https://github.com/Athology0000/cve-lab

https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026

https://github.com/Dungsocool/CVE-2017-10271

https://github.com/wyqsgy/vulnark

https://github.com/s4mjx/Portscanner-py

https://github.com/owlsecx/OSpecter

https://github.com/hermestoola/bb-hunter-pro

https://github.com/b1g-b33f/CVE-2020-14882

https://github.com/32BitZ-Studio/Total-POC-CVE

https://github.com/B1ack4sh/Blackash-CVE-2020-14883

https://github.com/B1ack4sh/Blackash-CVE-2020-14882

https://github.com/psibot/oracle-weblogic-vulnerable

https://github.com/g1san/Agents-for-Vulnerable-Dockers-and-related-Benchmarks

https://github.com/mr-won/WebLogic_CVE_2020_14882

https://github.com/KKC73/weblogic-cve-2020-14882

https://github.com/AleksaZatezalo/CVE-2020-14882-HoaxShell

https://github.com/AleksaZatezalo/CVE-2020-14882

https://github.com/KcanCurly/WurlyCVEs

https://github.com/PoSH-Father/CVE-2020-14882

https://github.com/H4shByte/CVE-2020-14882

https://github.com/kuckibf/Popular-CVEs

https://github.com/tahaafarooq/POC

https://github.com/kangvcar/Hacking-Write-ups

https://github.com/lolminerxmrig/Capricornus

https://github.com/kalikaneko/unvd

https://github.com/nice0e3/CVE-2020-14882_Exploit_Gui

https://github.com/kk98kk0/CVE-2020-14882

https://github.com/Yang0615777/PocList

https://github.com/1n7erface/PocList

https://github.com/milo2012/CVE-2020-14882

https://github.com/ShmilySec/CVE-2020-14882

https://github.com/3hm1ly/CVE-2020-14882

https://github.com/securitysqs/Web_Poc

https://github.com/adm1in/CodeTest

https://github.com/corelight/CVE-2020-14882-weblogicRCE

https://github.com/Ormicron/CVE-2020-14882-GUI-Test

https://github.com/murataydemir/CVE-2020-14883

https://github.com/murataydemir/CVE-2020-14882

https://github.com/NS-Sp4ce/CVE-2020-14882

https://github.com/GGyao/CVE-2020-14882_ALL

https://github.com/GGyao/CVE-2020-14882_POC

https://github.com/wsfengfan/cve-2020-14882

https://github.com/0thm4n3/cve-2020-14882

https://github.com/XTeam-Wing/CVE-2020-14882

https://github.com/Umarovm/-Patched-McMaster-University-Blind-Command-Injection

https://github.com/zhzyker/exphub

https://github.com/0xn0ne/weblogicScanner

https://www.oracle.com/security-alerts/cpuoct2020.html

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14882

http://packetstormsecurity.com/files/161128/Oracle-WebLogic-Server-12.2.1.0-Remote-Code-Execution.html

http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.html

http://packetstormsecurity.com/files/159769/Oracle-WebLogic-Server-Remote-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2020-10-21

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99997