CVE-2020-2883
CRITICAL KEV NUCLEIOracle Access Manager unauthenticated Remote Code Execution
Title source: metasploitDescription
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploits (11)
nomisec
WORKING POC
15 stars
by MagicZer0 · poc
https://github.com/MagicZer0/Weblogic_CVE-2020-2883_POC
nomisec
WORKING POC
2 stars
by FancyDoesSecurity · remote-auth
https://github.com/FancyDoesSecurity/CVE-2020-2883
gitlab
by java-exploit · poc
https://gitlab.com/penetration-test-learn/10vuln/java-exploit/CVE_2020_2546
metasploit
WORKING POC
NORMAL
by Quynh Le, Y4er, Shelby Pace, Steve Embling · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/weblogic_deserialize_badattr_extcomp.rb
Nuclei Templates (1)
Oracle WebLogic Server - Remote Code Execution
CRITICALVERIFIEDby daffainfo
Shodan:
product:"oracle weblogic"
References (5)
Scores
CVSS v3
9.8
EPSS
0.9436
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-01-07
VulnCheck KEV
2020-04-30
InTheWild.io
2020-05-04
ENISA EUVD
EUVD-2020-22676
Status
published
Products (4)
oracle/weblogic_server
10.3.6.0.0
oracle/weblogic_server
12.1.3.0.0
oracle/weblogic_server
12.2.1.3.0
oracle/weblogic_server
12.2.1.4.0
Published
Apr 15, 2020
KEV Added
Jan 07, 2025
Tracked Since
Feb 18, 2026