Vulnerability record · CVE-2020-14882 · published 21 October 2020
CVE-2020-14882: Oracle WebLogic Server Console unauthenticated remote code execution
Oracle · Weblogic Server
The Oracle WebLogic Server Console component contains an easily exploitable flaw that lets an unauthenticated attacker with network access take over the server over HTTP. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0, and carries a CVSS 3.1 base score of 9.8. Because the console is typically internet-reachable in exposed deployments, this is a high-value target for mass exploitation.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, confirmed public exploits, KEV listing and near-maximum EPSS probability makes this an urgent patch-first issue.
What it is
The Oracle WebLogic Server Console component contains an easily exploitable flaw that lets an unauthenticated attacker with network access take over the server over HTTP. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0, and carries a CVSS 3.1 base score of 9.8. Because the console is typically internet-reachable in exposed deployments, this is a high-value target for mass exploitation.
Impact
Successful exploitation results in full takeover of the WebLogic Server, with high confidentiality, integrity and availability impact. An attacker gains the ability to run code in the server's context and control the hosted applications and data.
Attack surface
Reached over the network via HTTP against the WebLogic Administration Console; the CVSS vector shows no privileges required (PR:N) and no user interaction (UI:N). Any host that exposes the console port to untrusted networks is directly reachable.
Exploitation
The vulnerability is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99997 (99.999th percentile), indicating active exploitation. Multiple references are tagged Exploit, confirming public exploit code exists.
What to do
- Apply the Oracle October 2020 Critical Patch Update (cpuoct2020) or a later patch for all affected WebLogic versions.
- Restrict network access to the WebLogic Administration Console so it is not reachable from the internet or untrusted networks.
- Disable or block the console path at the reverse proxy/WAF where the console is not required for operations.
- Run WebLogic with least privilege and isolate it from sensitive internal networks to limit post-exploitation movement.
- Monitor vendor advisories and CISA KEV for updated guidance and re-check exposure after patching.
Detection
- Inspect HTTP access logs for requests to the WebLogic Console path with unusual or encoded parameters, especially from unexpected source IPs.
- Alert on new or unexpected child processes spawned by the WebLogic Java process (for example shells or scripting interpreters).
- Monitor for outbound connections from WebLogic hosts to unfamiliar external addresses, which may indicate post-exploitation command and control.
- Review file system changes in WebLogic deployment and temporary directories for dropped payloads or webshells.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-14882 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle WebLogic Server Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-14882 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14882), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.