Code Injection in Oracle WebLogic Server - CVE-2020-14882
Published: October 29, 2020 / Updated: August 1, 2025
Vulnerability identifier: #VU48016
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14882
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Console component in Oracle WebLogic Server. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle WebLogic Server
RSA Authentication Manager
RSA Authentication Manager
How to mitigate CVE-2020-14882
Install updates from vendor's website.
RSA Authentication Manager - update to 8.5 Patch 2
Links to Public Exploits and PoC-codes
- Exploit #11824 - CVE-2020-14882 () (August 1, 2025)
- Exploit #9192 - CVE-2020-14882 (This script allows for remote code execution (RCE) on Oracle WebLogic Server) (July 19, 2023)
- Exploit #9016 - CVE-2020-14882 (CVE-2020-14882 rewritten in PowerShell) (April 28, 2023)
- Exploit #8980 - CVE-2020-14882 () (April 11, 2023)
- Exploit #8869 - CVE-2020-14882_ALL (综合利用工具) (February 26, 2023)
- Exploit #8705 - CVE-2020-14882- () (January 2, 2023)
- Exploit #8405 - StudyRoom ( Repository created for study and POC's on vulnerabilities.) (September 26, 2022)
- Exploit #7486 - CVE-2020-14882 (CVE-2020-14882部署冰蝎内存马) (March 14, 2022)
- Exploit #7183 - CVE-2020-14882 (CVE-2020-14882 Weblogic-Exp) (December 16, 2021)
- Exploit #6504 - CVE-2020-14882-14883 (结合14882的未授权访问漏洞,通过14883可远程执行任意代码) (July 4, 2021)
- Exploit #5400 - CVE-2020-14882-WebLogic (Check YouTube - https://youtu.be/O0ZnLXRY5Wo) (May 12, 2021)
- Exploit #5396 - CodeTest (CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。) (May 12, 2021)
- Exploit #5287 - cve-exploits () (April 12, 2021)
- Exploit #5229 - PocList (Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongy (March 18, 2021)
- Exploit #5182 - CVE-2020-14882 (CVE-2020-14882) (February 25, 2021)
- Exploit #5101 - CVE-2020-14882-WebLogic () (January 31, 2021)
- Exploit #5087 - CVE-2020-14882 (CVE-2020-14882部署冰蝎内存马) (January 28, 2021)
- Exploit #5085 - Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated) (January 27, 2021)
- Exploit #5035 - poc (CVE-2020-14882) (January 18, 2021)
- Exploit #4890 - -Patched-McMaster-University-Blind-Command-Injection ((patched) This targets McMaster University's website and takes advantage of CVE-2020-14882 in the outdated version of WebLogic Server (12.2.1.3.0), which is present in the university's subdomains, mosa (November 30, 2020)
- Exploit #4859 - Oracle WebLogic Server Administration Console Handle RCE (November 18, 2020)
- Exploit #4853 - CVE-2020-14882-weblogicRCE (Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750) (November 17, 2020)
- Exploit #4837 - CVE-2020-14882 () (November 13, 2020)
- Exploit #4823 - CVE-2020-14882-GUI-Test (基于qt的图形化CVE-2020-14882漏洞回显测试工具.) (November 11, 2020)
- Exploit #4813 - CVE-2020-14882 ([CVE-2020-14882] Oracle WebLogic Server Authentication Bypass) (November 10, 2020)
- Exploit #4811 - CVE-2020-14882 () (November 10, 2020)
- Exploit #4804 - cve-2020-14882 () (November 6, 2020)
- Exploit #4792 - CVE-2020-14882 (CVE-2020-14882/14883/14750) (November 4, 2020)
- Exploit #4790 - cve-2020-14882 (CVE-2020-14882 EXP 回显) (November 3, 2020)
- Exploit #4788 - McMaster-University-0-day-Blind-Command-Injection ((patched) This targets McMaster University's website and takes advantage of CVE-2020-14882 in the outdated version of WebLogic Server (12.2.1.3.0), which is present in the university's subdomains, mosaic. (November 3, 2020)
- Exploit #4786 - cve-2020-14882 (Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882) (November 3, 2020)
- Exploit #4785 - CVE-2020-14882 () (November 3, 2020)
- Exploit #4783 - Weblogic_Unauthorized-bypass-RCE ((CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script) (November 3, 2020)
- Exploit #4780 - falcon (Collection of exploits that were verified by an automated system) (November 3, 2020)
- Exploit #4779 - CVE-2020-14882 (CVE-2020-14882批量验证工具。) (November 3, 2020)
- Exploit #4778 - CVE-2020-14882_POC (CVE-2020-14882批量验证工具。) (November 3, 2020)
- Exploit #4777 - CVE-2020-14882-checker (CVE-2020-14882 detection script) (November 3, 2020)
- Exploit #4774 - CVE-2020-14882_ALL (CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。) (November 3, 2020)
- Exploit #4772 - CVE-2020-14882 (CVE-2020–14882、CVE-2020–14883) (October 30, 2020)
- Exploit #4771 - WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE via GET request (October 30, 2020)
- Exploit #4770 - CVE-2020-14882 (CVE-2020–14882 by Jang) (October 30, 2020)
- Exploit #4769 - CVE-2020-14882 (CVE-2020-14882 Weblogic-Exp) (October 30, 2020)