CVE-2020-14750 is a critical vulnerability in the Console component of Oracle WebLogic Server affecting versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. It is a bypass of Oracle’s initial fix for CVE-2020-14882. The flaw arises from insufficient validation of request paths in the administrative console, where blacklist-based URL filtering can be evaded through encoded traversal sequences that are decoded during request processing. This allows an unauthenticated remote attacker to reach restricted console resources that should require authentication. In practical exploit chains, access to the console endpoint can then be combined with the related console request handling issue associated with CVE-2020-14883 to achieve unauthenticated remote code execution. Oracle rates the issue as easily exploitable over HTTP with no authentication required, and successful exploitation can result in takeover of Oracle WebLogic Server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a Bash-based proof-of-concept (PoC) exploit and a detection script for Oracle WebLogic vulnerabilities CVE-2020-14750 and CVE-2020-14882. The main exploit script, 'CVE-2020-14750.sh', takes a target host:port and a command to execute, then crafts a POST request to the vulnerable WebLogic endpoint '/console/css/%252e%252e%252fconsole.portal'. The payload is a serialized MVEL expression that leverages Java reflection to execute the supplied command on the server, returning the output in the HTTP response. The detection script, 'test-CVE-2020-14750.sh', automates checking if the exploit is successful by running a benign command and analyzing the response. The repository is operational, providing both exploitation and detection capabilities for the specified CVEs. No hardcoded IPs or domains are present; the target is supplied by the user at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Oracle 對 CVE-2020-14882 的不完整修補所衍生出的繞過漏洞,可利用未被黑名單阻擋的編碼形式繞過 URL 檢查。
An Oracle WebLogic Server remote code execution vulnerability abused in cryptocurrency-mining attacks.
A related Oracle WebLogic Server path traversal vulnerability used for initial access; described as essentially the same as CVE-2020-14882 but with a more comprehensive fix, enabling admin console access and unauthenticated remote code execution when exploited.
A related WebLogic vulnerability variation that can be exploited with trivial modifications to existing exploit code for CVE-2020-14882.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.