CVE-2020-14883
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
- Affected products
- Oracle Weblogic Server
- Oracle Weblogic Server
- = 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 97.9% (100th percentile)
- NVD status
- Analyzed
- Published
- 2020-10-21
CVE-2020-14883 at NVD
17 known exploits for CVE-2020-14883
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-14883
CVE-2020-14883
CVE-2020-14883EXP
CVE-2020-14883
westone-CVE-2020-14883-scanner
CVE-2020-14882-14883
weblogicScanner
CVE-2020-14882-WebLogic-Analysis
CVE-2020-14882
CVE-Web-Framework
Exploit for CVE-2020-14882
Exploit for CVE-2020-14883
Oracle WebLogic Server Administration Console Handle Remote Code Execution Exploit
Oracle WebLogic Server Administration Console Handle Remote Code Execution
Exploit for CVE-2020-14883
Exploit for CVE-2020-14883
Exploit for CVE-2020-14882