CVE-2020-2883 is an insecure deserialization vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. It affects supported WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0. An unauthenticated remote attacker able to reach the IIOP or T3 services can submit crafted protocol requests to compromise and take over the affected WebLogic Server instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'weblogic_deserialize_badattr_extcomp.rb', which exploits a Java deserialization vulnerability (CVE-2020-2883) in Oracle WebLogic Server. The exploit targets the T3 protocol (default port 7001) and leverages a crafted BadAttributeValueExpException object with an ExtractorComparator to achieve unauthenticated remote code execution. The module supports both Windows and Unix/Linux targets, delivering either a Meterpreter reverse shell or arbitrary shell commands. The exploit is weaponized, allowing for customizable payloads and reliable exploitation. The module includes version detection logic by sending an HTTP request to '/console/login/LoginForm.jsp' and parsing the response for the WebLogic version. The code is written in Ruby and is structured as a standard Metasploit exploit module, making use of Metasploit's TCP, command stager, and PowerShell mixins. No hardcoded IP addresses or domains are present, but the default port and HTTP path used for fingerprinting are notable endpoints.
This repository is a comprehensive exploit library (exphub) containing operational exploit scripts for a wide range of high-profile vulnerabilities affecting popular enterprise software. The structure is organized by product (e.g., drupal/, f5/, fastjson/, jboss/, nexus/, ofbiz/, shiro/, solr/, spring/, struts2/, tomcat/, weblogic/), with each directory containing Python or Java scripts for specific CVEs. The scripts are primarily remote code execution (RCE) exploits, but also include file read, webshell upload, SSRF, and administrative bypasses. Many scripts provide interactive shells or allow arbitrary command execution, and some require authentication. The repository includes both proof-of-concept (POC) and full exploit scripts, with detailed usage instructions embedded in the code and readme files. The attack vector is predominantly network-based, targeting HTTP(S) endpoints, and the scripts are suitable for both vulnerability validation and exploitation. The codebase is mature, with operational exploits for each vulnerability, and is a valuable resource for penetration testers and red teamers.
This repository provides operational exploits for three Oracle WebLogic Server vulnerabilities: CVE-2020-2551, CVE-2020-2555, and CVE-2020-2883. The structure includes a Java-based exploit for CVE-2020-2551 (in CVE-2020-2551/src/exp.java) and two Python scripts for CVE-2020-2555 and CVE-2020-2883 (in CVE-2020-2555/CVE20202555Exp.py and CVE-2020-2883/CVE20202883Exp.py). The Java exploit leverages IIOP deserialization to trigger command execution, using callback domains (win.wb2551.starsosectest.starso.cn, lin.wb2551.starsosectest.starso.cn) to verify success. The Python scripts exploit the T3 protocol to send serialized payloads that execute arbitrary commands on the target. The exploits are configurable, allowing the attacker to specify the target URL and command to execute. The repository is well-structured, with clear separation for each CVE and supporting build files for the Java exploit. The main purpose is to provide proof-of-concept and operational exploit code for remote command execution on vulnerable WebLogic servers.
This repository contains a Java exploit for CVE-2020-2883, a deserialization vulnerability in Oracle WebLogic Server. The main file, CVE_2020_2883.java, constructs a malicious serialized Java object (using PriorityQueue and a chain of ReflectionExtractors) that, when deserialized by a vulnerable WebLogic instance, results in arbitrary command execution. The exploit sends the payload over the T3 protocol to a specified target IP and port (default 7001). The provided payload attempts to execute a shell command that performs a curl request to 172.16.1.1, serving as a proof of code execution. The repository also includes a README with basic usage instructions. The exploit is operational and demonstrates remote code execution, but the payload is hardcoded and would need to be modified for other commands or callback addresses.
This repository is a proof-of-concept (POC) exploit for Oracle WebLogic Server CVE-2020-2883, a deserialization vulnerability that allows remote code execution. The core of the exploit is implemented in two Java files: Gadget1.java and Gadget2.java. Both files construct malicious Java object gadget chains (using classes such as BadAttributeValueExpException, PriorityQueue, and various Coherence extractors) that, when deserialized by a vulnerable WebLogic server, result in arbitrary command execution via Runtime.exec(). The payload in the POC launches Calculator.app as a demonstration, but this can be replaced with any system command. The exploit requires the Oracle Coherence library and must be delivered to the target using a T3 protocol request, which is not included in the code and must be constructed separately. The repository includes Maven build files and IntelliJ IDEA project files, but the main exploit logic resides in the two Java source files. No hardcoded network endpoints are present, but the attack vector is network-based, targeting the WebLogic T3 service.
This repository is a comprehensive Java exploit and demonstration suite focused on Java deserialization vulnerabilities, particularly targeting Oracle WebLogic (CVE-2020-2555, CVE-2020-2883) and Apache Shiro (Shiro-550). The structure includes: - CVE exploits: `src/main/java/org/chabug/cve/CVE_2020_2555.java` and `CVE_2020_2883.java` implement gadget chains that exploit deserialization flaws to achieve remote code execution (RCE) on vulnerable WebLogic servers. - Shiro-550 exploit: `src/main/java/org/chabug/shiro/Shiro550.java` crafts a malicious rememberMe cookie using a hardcoded key to exploit Apache Shiro's deserialization vulnerability. - Memory shell (web shell) injection: The `memshell` directory contains code (`AntSwordFilterShell.java`, `InjectFilterShell.java`, `CVE_2020_2883_URLClassLoader.java`) to inject a filter-based memory shell into a running Java web application, providing persistent access and a wide range of post-exploitation capabilities (file management, command execution, SQL queries, etc.). - Demo and utility code: The `demo` directory provides various proof-of-concept payloads, gadget chains (CommonsCollections2/5), and serialization utilities. The `loader` directory demonstrates dynamic class loading techniques, including loading classes from local and remote JARs. The main exploit capabilities are: - Achieving RCE via Java deserialization gadget chains (CommonsCollections, WebLogic, Shiro) - Injecting a memory shell for persistent access and post-exploitation - Demonstrating dynamic class loading and reflection-based attacks Fingerprintable endpoints include file paths for malicious JARs and class files used in the exploitation process. The attack vector is primarily network-based, exploiting deserialization over HTTP (e.g., via cookies or serialized input). The code is operational and can be adapted for real-world exploitation with minor modifications.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Oracle Coherence vulnerability referenced as the source of a verified template whose T3 wrapper and ReflectionExtractor deserialization sink are reused for CVE-2020-2555.
A critical Oracle WebLogic Server vulnerability that can be exploited by an unauthenticated attacker with network access via IIOP or T3 to compromise the server.
A critical, easily exploitable Oracle WebLogic Server (Fusion Middleware Core) vulnerability that allows an unauthenticated remote attacker with network access (via IIOP/T3) to compromise and potentially take over the WebLogic Server.
A remote code execution vulnerability in Oracle WebLogic Server, referenced in the context of creating a Nuclei detection template (KEV).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.