Improper input validation in Oracle WebLogic Server - CVE-2020-2551
Published: February 7, 2020 / Updated: November 16, 2023
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the WLS Core Components component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
How to mitigate CVE-2020-2551
Links to Public Exploits and PoC-codes
- Exploit #8833 - CVE-2020-2551 () (February 13, 2023)
- Exploit #7950 - CVE-Exploit (CVE-2020-2551 Exploiter ) (June 2, 2022)
- Exploit #4556 - defvul (Weblogic CVE-2020-14645 coherence 反序列化漏洞验证程序) (September 1, 2020)
- Exploit #2902 - CVE-2020-2551 (Use shell to build weblogic debug environment for CVE-2020-2551) (June 3, 2020)
- Exploit #2979 - weblogicPoc (Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。) (June 3, 2020)
- Exploit #2999 - Weblogic-CVE-2020-2551-To-Internet (CVE-2020-2551 POC to use in Internet) (June 3, 2020)
- Exploit #2817 - CVE-2020-2551 (Weblogic RCE with IIOP) (June 3, 2020)
- Exploit #2895 - rmi-iiop (复现cve-2020-2551的基础学习) (June 3, 2020)
- Exploit #2274 - exphub (Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340) (April 7, 2020)
- Exploit #300 - CVE-2020-2551 (Weblogic IIOP CVE-2020-2551) (March 18, 2020)
- Exploit #301 - weblogicScanner (weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2 (March 18, 2020)
- Exploit #302 - CVE-2020-2551 (how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP) (March 18, 2020)
- Exploit #303 - CVE-2020-2551 (CVE-2020-2551) (March 18, 2020)