CVE-2020-2551

CRITICAL KEV NUCLEI

Oracle WebLogic Server <12.2.1.4 - RCE

Title source: llm

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (12)

nomisec SCANNER 2,072 stars
by 0xn0ne · remote
https://github.com/0xn0ne/weblogicScanner
nomisec WORKING POC 340 stars
by Y4er · remote
https://github.com/Y4er/CVE-2020-2551
nomisec SCANNER 211 stars
by hktalent · remote
https://github.com/hktalent/CVE-2020-2551
nomisec WORKING POC 92 stars
by zzwlpx · poc
https://github.com/zzwlpx/weblogicPoc
nomisec WRITEUP 80 stars
by jas502n · poc
https://github.com/jas502n/CVE-2020-2551
nomisec WORKING POC 22 stars
by Dido1960 · poc
https://github.com/Dido1960/Weblogic-CVE-2020-2551-To-Internet
nomisec SCANNER 1 stars
by abbarhissarh · poc
https://github.com/abbarhissarh/CVE-Exploit
nomisec SCANNER 1 stars
by ar2o3 · poc
https://github.com/ar2o3/CVE-Exploit
gitlab WORKING POC
by milo2012 · poc
https://gitlab.com/milo2012/cve-2020-2551
nomisec WORKING POC
by DaMinGshidashi · poc
https://github.com/DaMinGshidashi/CVE-2020-2551
vulncheck_xdb SCANNER
remote
https://github.com/0xAbbarhSF/CVE-Exploit

Nuclei Templates (1)

Oracle WebLogic Server - Remote Code Execution
CRITICALby dwisiswant0
Shodan: http.title:"oracle peoplesoft sign-in" || product:"oracle weblogic"
FOFA: title="oracle peoplesoft sign-in"

Scores

CVSS v3 9.8
EPSS 0.9441
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-11-16
VulnCheck KEV 2023-06-02
InTheWild.io 2021-12-04
ENISA EUVD EUVD-2020-22344
Status published
Products (4)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
oracle/weblogic_server 12.2.1.4.0
Published Jan 15, 2020
KEV Added Nov 16, 2023
Tracked Since Feb 18, 2026