CVE-2020-14883

HIGH KEV NUCLEI

Oracle WebLogic Server <14.1.1.0.0 - RCE

Title source: llm

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Exploits (10)

nomisec WRITEUP 1,079 stars
by 1n7erface · poc
https://github.com/1n7erface/PocList
nomisec WORKING POC 13 stars
by murataydemir · remote
https://github.com/murataydemir/CVE-2020-14883
nomisec SCANNER 7 stars
by B1anda0 · remote
https://github.com/B1anda0/CVE-2020-14883
nomisec WORKING POC 5 stars
by fan1029 · poc
https://github.com/fan1029/CVE-2020-14883EXP
nomisec WORKING POC
by amacloudobia · infoleak
https://github.com/amacloudobia/CVE-2020-14883
nomisec SCANNER
by Osyanina · poc
https://github.com/Osyanina/westone-CVE-2020-14883-scanner
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner
metasploit WORKING POC EXCELLENT
by voidfyoo, Jang, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/weblogic_admin_handle_rce.rb

Nuclei Templates (1)

Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution
HIGHVERIFIEDby pdteam,vicrack
Shodan: title:"Oracle PeopleSoft Sign-in" || product:"oracle weblogic" || http.title:"oracle peoplesoft sign-in"
FOFA: title="oracle peoplesoft sign-in"

Scores

CVSS v3 7.2
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-7019
Status published
Products (5)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
oracle/weblogic_server 12.2.1.4.0
oracle/weblogic_server 14.1.1.0.0
Published Oct 21, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026