Improper input validation in Oracle WebLogic Server - CVE-2020-14883
Published: October 29, 2020 / Updated: January 10, 2023
Vulnerability identifier: #VU48029
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14883
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Console component in Oracle WebLogic Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle WebLogic Server
RSA Authentication Manager
RSA Authentication Manager
How to mitigate CVE-2020-14883
Install updates from vendor's website.
RSA Authentication Manager - update to 8.5 Patch 2
Links to Public Exploits and PoC-codes
- Exploit #6505 - CVE-2020-14882-14883 (结合14882的未授权访问漏洞,通过14883可远程执行任意代码) (July 4, 2021)
- Exploit #5228 - PocList (Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongy (March 18, 2021)
- Exploit #5181 - westone-CVE-2020-14883-scanner (A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.) (February 25, 2021)
- Exploit #5083 - CVE-2020-14883EXP (用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用) (January 26, 2021)
- Exploit #4858 - Oracle WebLogic Server Administration Console Handle RCE (November 18, 2020)
- Exploit #4822 - CVE-2020-14883 (Weblogic 身份认证绕过漏洞批量检测脚本) (November 11, 2020)
- Exploit #4814 - CVE-2020-14883 ([CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)) (November 10, 2020)