← back
CVE-2020-14882criticalunder attack

CVE-2020-14882

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon0 days
Published on NVDOct 21
1st PoCJul 18
metasploitOct 20
CISA KEV+378d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
80 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

Summary

Falha de path traversal no Console de administração do Oracle WebLogic Server que permite a um atacante não autenticado, via HTTP, contornar a autenticação e alcançar handlers internos do console normalmente protegidos por login. Na prática essa CVE é explorada em conjunto com uma segunda falha (deserialização/RCE, catalogada separadamente) para obter execução remota de código completa, o que a torna uma das cadeias mais exploradas em massa da história recente do WebLogic — exploração ativa começou em horas após a publicação do patch de outubro/2020.

Technical detail

A vulnerabilidade está no componente Console do WebLogic e é uma falha de path traversal (CWE-22) na forma como o servidor resolve URLs de recursos estáticos (imagens, CSS) dentro do console administrativo. Usando sequências de path traversal codificadas (barras e pontos codificados em URL, ex. variações de %2E%2E%2F) em caminhos como os que servem imagens do console, um atacante consegue fazer o servidor tratar a requisição como interna, contornando o filtro de autenticação que normalmente bloqueia acesso não autenticado a `/console/console.portal` e páginas administrativas correlatas.

O bypass em si só concede acesso não autenticado a telas e handlers do console que deveriam exigir login — já é grave porque expõe funcionalidades administrativas, mas não é RCE por si só. A cadeia de exploração observada na prática combina esse bypass com uma segunda falha (rastreada como CVE-2020-14750, e posteriormente reforçada por CVE-2020-14883) que permite, a partir de um handler acessível pelo bypass, acionar deserialização insegura ou invocação de classe controlada pelo atacante, resultando em execução arbitrária de comandos no contexto do processo WebLogic.

O atacante controla o payload embutido na URL/parâmetros da requisição HTTP direcionada ao console; não precisa de credenciais, sessão prévia nem interação do usuário. A superfície é a interface HTTP do console administrativo, tipicamente exposta nas portas padrão de administração do WebLogic (7001/7002 ou equivalentes configuradas).

Researched and written with AI from the vendor advisory and public analysis, with the sources above. Always confirm the fixed version in the official advisory before acting.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found80
exploitdbwww.exploit-db.com/exploits/49479unverifiedgithubgithub.com/zhzyker/exphub4291githubgithub.com/jas502n/CVE-2020-14882288githubgithub.com/GGyao/CVE-2020-14882_ALL145githubgithub.com/s1kr10s/CVE-2020-1488229githubgithub.com/NS-Sp4ce/CVE-2020-1488219githubgithub.com/XTeam-Wing/CVE-2020-1488217githubgithub.com/adm1in/CodeTest13githubgithub.com/GGyao/CVE-2020-14882_POC12githubgithub.com/milo2012/CVE-2020-148828githubgithub.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE8githubgithub.com/QmF0c3UK/CVE-2020-148827githubgithub.com/wsfengfan/cve-2020-148827githubgithub.com/corelight/CVE-2020-14882-weblogicRCE7githubgithub.com/xfiftyone/CVE-2020-148825githubgithub.com/murataydemir/CVE-2020-148823githubgithub.com/exploitblizzard/CVE-2020-14882-WebLogic3githubgithub.com/kk98kk0/CVE-2020-148823githubgithub.com/mmioimm/cve-2020-148823githubgithub.com/Danny-LLi/CVE-2020-148822githubgithub.com/Ormicron/CVE-2020-14882-GUI-Test2githubgithub.com/0thm4n3/cve-2020-148822githubgithub.com/N0Coriander/CVE-2020-14882-148832githubgithub.com/b1g-b33f/CVE-2020-148821githubgithub.com/ovProphet/CVE-2020-14882-checker1githubgithub.com/KKC73/weblogic-cve-2020-148820githubgithub.com/alexfrancow/CVE-2020-148820githubgithub.com/BabyTeam1024/CVE-2020-148820githubgithub.com/pwn3z/CVE-2020-14882-WebLogic0githubgithub.com/nik0nz7/CVE-2020-148820githubgithub.com/Root-Shells/CVE-2020-148820githubgithub.com/zesnd/CVE-2020-14882-POC0githubgithub.com/qianniaoge/CVE-2020-14882_Exploit_Gui0githubgithub.com/LucasPDiniz/CVE-2020-148820githubgithub.com/xMr110/CVE-2020-148820githubgithub.com/AleksaZatezalo/CVE-2020-148820vulncheckvulncheck.com/xdb/a0b529fd1da1unverifiedvulncheckvulncheck.com/xdb/0b1c82ba94b9unverifiedvulncheckvulncheck.com/xdb/8adc0b8f62e1unverifiedvulncheckvulncheck.com/xdb/b5dce10a0a8bunverifiedvulncheckvulncheck.com/xdb/9614336da46dunverifiedcve_referencepacketstormsecurity.com/files/159769/Oracle-WebLogic-Server-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/164322952fd0unverifiedcve_referencepacketstormsecurity.com/files/160143/Oracle-WebLogic-Server-Administration-Console-Handle-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/f699189c90f2unverifiedcve_referencepacketstormsecurity.com/files/161128/Oracle-WebLogic-Server-12.2.1.0-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/e962ac877371unverifiedvulncheckvulncheck.com/xdb/59c38bcb5664unverifiedvulncheckvulncheck.com/xdb/c05a01763211unverifiedvulncheckvulncheck.com/xdb/da9f3f6e7e1funverifiedvulncheckvulncheck.com/xdb/78305831909cunverifiedvulncheckvulncheck.com/xdb/1219b099cdb5unverifiedvulncheckvulncheck.com/xdb/65ab3b9c2ebaunverifiedvulncheckvulncheck.com/xdb/fb1c79c789bdunverifiedvulncheckvulncheck.com/xdb/72df0e276603unverifiedvulncheckvulncheck.com/xdb/3b3ffa595f0cunverifiedvulncheckvulncheck.com/xdb/c13d71ba7622unverifiedvulncheckvulncheck.com/xdb/7abe5b874cdfunverifiedvulncheckvulncheck.com/xdb/0973a77bd68eunverifiedvulncheckvulncheck.com/xdb/7c45f41c9580unverifiedvulncheckvulncheck.com/xdb/088ca7d07c62unverifiedvulncheckvulncheck.com/xdb/49e9f36f16d8unverifiedvulncheckvulncheck.com/xdb/7232b7797539unverifiedvulncheckvulncheck.com/xdb/2539687dc0eeunverifiedvulncheckvulncheck.com/xdb/5f6f99d250bdunverifiedvulncheckvulncheck.com/xdb/1bc750482298unverifiedvulncheckvulncheck.com/xdb/8270081cbc20unverifiedvulncheckvulncheck.com/xdb/358f9960e478unverifiedvulncheckvulncheck.com/xdb/ce68066c259eunverifiedvulncheckvulncheck.com/xdb/a13fcf8de8fcunverifiedvulncheckvulncheck.com/xdb/5adef887fb7eunverifiedvulncheckvulncheck.com/xdb/263de78f8cf4unverifiedvulncheckvulncheck.com/xdb/8035aa262c64unverifiedvulncheckvulncheck.com/xdb/b539b7bd0520unverifiedvulncheckvulncheck.com/xdb/ee66647244c0unverifiedvulncheckvulncheck.com/xdb/d3a3f91fa307unverifiedvulncheckvulncheck.com/xdb/179b4fcf93efunverifiedvulncheckvulncheck.com/xdb/91590177ee0dunverifiedvulncheckvulncheck.com/xdb/9476c651d5c0unverifiedvulncheckvulncheck.com/xdb/038d453cd70dunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.