CVE-2020-2883

CRITICAL KEV NUCLEI

Oracle Access Manager unauthenticated Remote Code Execution

Title source: metasploit

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (11)

nomisec WORKING POC 535 stars
by Y4er · remote
https://github.com/Y4er/WebLogic-Shiro-shell
nomisec WORKING POC 176 stars
by Y4er · remote
https://github.com/Y4er/CVE-2020-2883
nomisec WORKING POC 15 stars
by MagicZer0 · poc
https://github.com/MagicZer0/Weblogic_CVE-2020-2883_POC
nomisec WORKING POC 5 stars
by Al1ex · remote
https://github.com/Al1ex/CVE-2020-2883
nomisec WORKING POC 2 stars
by FancyDoesSecurity · remote-auth
https://github.com/FancyDoesSecurity/CVE-2020-2883
nomisec WORKING POC
by Qynklee · remote
https://github.com/Qynklee/POC_CVE-2020-2883
nomisec STUB
by ZZZWD · poc
https://github.com/ZZZWD/CVE-2020-2883
vulncheck_xdb WORKING POC
remote
https://github.com/zzwlpx/weblogicPoc
vulncheck_xdb SCANNER
remote
https://github.com/0xn0ne/weblogicScanner
metasploit WORKING POC NORMAL
by Quynh Le, Y4er, Shelby Pace, Steve Embling · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_badattr_extcomp.rb

Nuclei Templates (1)

Oracle WebLogic Server - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan: product:"oracle weblogic"

Scores

CVSS v3 9.8
EPSS 0.9436
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-01-07
VulnCheck KEV 2020-04-30
InTheWild.io 2020-05-04
ENISA EUVD EUVD-2020-22676
Status published
Products (4)
oracle/weblogic_server 10.3.6.0.0
oracle/weblogic_server 12.1.3.0.0
oracle/weblogic_server 12.2.1.3.0
oracle/weblogic_server 12.2.1.4.0
Published Apr 15, 2020
KEV Added Jan 07, 2025
Tracked Since Feb 18, 2026