Vulnerability record · CVE-2020-14883 · published 21 October 2020
CVE-2020-14883: Oracle WebLogic Server Console remote code execution
Oracle · Weblogic Server
Oracle WebLogic Server's Console component contains an unspecified flaw that lets a high-privileged attacker with network access take over the server. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Because it is in the administration console and leads to full server compromise, it is a serious post-authentication risk on internet-exposed instances.
Description
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with full confidentiality, integrity and availability impact, plus KEV listing and near-maximum EPSS, make this a high-priority target despite the required admin privileges.
What it is
Oracle WebLogic Server's Console component contains an unspecified flaw that lets a high-privileged attacker with network access take over the server. It affects versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Because it is in the administration console and leads to full server compromise, it is a serious post-authentication risk on internet-exposed instances.
Impact
An attacker who already holds administrative credentials can execute code and fully take over the WebLogic Server, gaining control of confidentiality, integrity and availability.
Attack surface
Reached over the network via HTTP against the WebLogic administration console. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so valid admin-level access is needed.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS probability is 0.979 (99.9th percentile), indicating active exploitation in the wild. Reference tags are vendor and third-party advisories only; no public exploit code is described in the record.
What to do
- Apply the Oracle October 2020 Critical Patch Update for WebLogic Server (cpuoct2020) to all affected versions.
- Restrict network access to the WebLogic administration console; do not expose it to the internet.
- Enforce strong, unique administrative credentials and least-privilege accounts for console access.
- Monitor for and remove any unauthorized deployments or configuration changes on WebLogic instances.
Detection
- Alert on unexpected HTTP requests to WebLogic console paths, especially those followed by new application deployments.
- Monitor WebLogic logs for administrative console logins from unusual source IPs or at unusual times.
- Watch for new or modified WAR/EAR deployments and spawned child processes from the WebLogic JVM.
- Correlate outbound network connections from WebLogic hosts with known post-exploitation behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-14883 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Oracle WebLogic Server Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.h | Third Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Vendor Advisory |
| http://packetstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.h | Third Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuoct2020.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-14883 | US Government Resource |
Track CVE-2020-14883 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14883), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.