Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Unauthenticated RCE in Oracle WebLogic Server Console

IdentifiersCVE-2020-14750CWE-22

CVE-2020-14750 is an easily exploitable vulnerability in the Console component of Oracle WebLogic Server affecting supported versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The provided content states that the issue is reachable over HTTP by an unauthenticated attacker and is associated with a path traversal condition that can expose or bypass protections around the WebLogic administrative console. The referenced reporting further indicates that this access can be leveraged for unauthenticated remote code execution, and Oracle characterizes successful exploitation as resulting in takeover of Oracle WebLogic Server.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow a remote, unauthenticated attacker to compromise the affected Oracle WebLogic Server over HTTP. The content states this can result in takeover of the server, with high confidentiality, integrity, and availability impact (CVSS 3.1 base score 9.8). Supporting advisory material further indicates arbitrary code execution is possible, enabling full server compromise and follow-on attacker activity.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict network access to WebLogic Server, especially HTTP access to the administrative console and other public-facing interfaces, limit exposure to trusted management networks only, and monitor closely for suspicious requests and post-exploitation activity. These measures are only temporary risk reductions and do not replace applying Oracle's patch.

Remediation

Patch, then assume compromise.

Apply Oracle's security fix for CVE-2020-14750 from the October 2020 patch bundle / relevant Oracle security update, or upgrade to a fixed Oracle WebLogic Server version as specified by Oracle. The content explicitly states the updates should be deployed immediately. Ensure the deployment is on a supported release eligible for Oracle security patches.
PUBLIC EXPLOITS

Exploits

1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).

VALID 1 / 2 TOTALView more in app
CVE-2020-14750MaturityPoCVerified exploit

This repository provides a Bash-based proof-of-concept (PoC) exploit and a detection script for Oracle WebLogic vulnerabilities CVE-2020-14750 and CVE-2020-14882. The main exploit script, 'CVE-2020-14750.sh', takes a target host:port and a command to execute, then crafts a POST request to the vulnerable WebLogic endpoint '/console/css/%252e%252e%252fconsole.portal'. The payload is a serialized MVEL expression that leverages Java reflection to execute the supplied command on the server, returning the output in the HTTP response. The detection script, 'test-CVE-2020-14750.sh', automates checking if the exploit is successful by running a benign command and analyzing the response. The repository is operational, providing both exploitation and detection capabilities for the specified CVEs. No hardcoded IPs or domains are present; the target is supplied by the user at runtime.

pprietosanchezDisclosed Nov 6, 2020bashnetwork
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleWeblogic Serverapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.