CVE-2020-14883 is an improper access-control vulnerability in the Oracle WebLogic Server Console component. It affects WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. A high-privileged attacker with HTTP network access can exploit the Console component to compromise the WebLogic Server. The issue has frequently been operationally chained with CVE-2020-14882, which can bypass administrative-console authentication, to enable unauthenticated remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
Small repository containing a write-up and a single Java proof-of-concept payload for exploiting the Oracle WebLogic Server CVE-2020-14882/CVE-2020-14883 chain. Structure is minimal: README.md provides the exploitation narrative, reconnaissance examples, vulnerable path pattern, and detection guidance; poc/exploit_payload.java contains the core payload logic. The exploit targets Oracle WebLogic Server 12.2.1.3 and uses a web attack path: first, an authentication bypass via double-encoded path traversal to /console.portal; second, code execution through a WebLogic/MVEL-related execution path. The Java payload is not a standalone program but a code fragment intended to run inside the vulnerable WebLogic execution context. It hijacks the current WebLogic worker thread, reflectively accesses the connection handler, obtains request/response objects, reads an attacker-controlled command from the X-CMD-HEADER header, executes it through cmd.exe or /bin/sh depending on the OS, captures stdout, and writes the output directly into the HTTP response stream. This gives the operator in-band command execution results rather than blind RCE. The repository is a real exploit PoC rather than a detector or fake sample, but it is operational rather than weaponized because it provides a hardcoded payload concept without a full delivery framework or customizable exploit tooling.
This repository contains a single Metasploit module targeting Oracle WebLogic Server's Administration Console for remote code execution (RCE) via a path traversal and Java class instantiation vulnerability. The exploit leverages crafted HTTP POST requests to the '/console/css/.%252e/console.portal' endpoint, abusing the 'handle' parameter to trigger code execution. It supports multiple payload types, including direct command execution and Meterpreter reverse shells, across Unix/Linux and Windows platforms. The module is weaponized, allowing for easy payload customization and automated exploitation. It targets CVE-2020-14882, CVE-2020-14883, and CVE-2020-14750, affecting WebLogic versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The code is structured as a standard Metasploit exploit module, with clear separation of check, exploit, and payload delivery logic. The only file present is the Ruby module itself, which is fully self-contained and ready for use within the Metasploit framework.
This repository contains a Python proof-of-concept exploit targeting Oracle WebLogic Server. The main file, 'weblogic.py', sends a crafted POST request to the '/console/images/%252E%252E%252Fconsole.portal' endpoint on the target server, attempting to exploit a vulnerability that allows remote code execution via the 'com.tangosol.coherence.mvel2.sh.ShellSession' class. The payload executes the 'ipconfig' command to fingerprint the operating system. The script checks the response for evidence of Windows OS and reports if the target is vulnerable. The README.md provides an example of a similar payload and a sample HTTP request. The exploit requires the attacker to specify the target's IP and port, and the target must be accessible over the network. No CVE is explicitly referenced, but the exploit is clearly aimed at WebLogic's remote code execution vulnerabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Oracle WebLogic Server console vulnerability used in the article to trigger remote XML loading and validate blind-SSRF reachability.
An older Oracle WebLogic Server remote code execution vulnerability referenced as still being targeted alongside CVE-2026-21962 in attacks against WebLogic environments.
A critical Oracle WebLogic Server remote code execution flaw referenced alongside CVE-2020-14882 as part of the Console RCE issue set and observed in exploitation attempts against honeypots.
A critical Oracle WebLogic Server remote code execution vulnerability affecting the administrative console and involving authentication bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.