CVE-2020-14883 is a remote code execution vulnerability in the Console component of Oracle WebLogic Server, part of Oracle Fusion Middleware. Affected supported versions are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. Crafted console requests can abuse handle processing to instantiate attacker-selected Java classes with attacker-controlled arguments, enabling execution through MVEL and reflection or loading malicious Spring application contexts. Exploitation of the vulnerability alone requires a highly privileged attacker with HTTP network access. It is commonly chained with the separate authentication bypass vulnerability CVE-2020-14882 to enable unauthenticated remote code execution. Successful exploitation can result in takeover of WebLogic Server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This 32-file repository is a deliberately vulnerable training environment with valid manual exploit examples, not a standalone automated exploit tool. CVE-2020-14882 bypasses console authentication through double-encoded traversal under /console/css/; CVE-2020-14883 then uses the handle parameter to instantiate classes capable of command execution. English and Chinese walkthroughs in app/ describe ShellSession/Runtime.exec and remotely loaded Spring XML/ProcessBuilder techniques. Their basic payloads create marker files; the CTF metadata requests a shell, but no shell payload is included. CVE-2019-2725 is mentioned only as historical context for the Spring technique, not as a targeted vulnerability. isoloom.yml is the authoritative lab specification. Generated .isoloom/ artifacts cover Docker Compose, Kubernetes/Kustomize, Vagrant, Proxmox, and six cloud Terraform backends: AWS, Azure, DigitalOcean, GCP, Linode, and OCI. app/ contains the vendored Vulhub walkthroughs and original minimal Compose manifest. base/ contains a one-line Oracle-image reference Dockerfile, explicitly documented as not the exact build source of the deployed vulhub/weblogic:12.2.1.3-2018 image. The 14 code/build files comprise seven Terraform files, one Ruby Vagrantfile, five shell scripts, and one Dockerfile; declarative YAML manifests and CI workflows are excluded from that count. Exploit Java/MVEL, XML, and bash snippets appear within Markdown rather than standalone source files. The checks establish console availability, a displayed 12.2.1.3 version, and blocked external HTTP access; they do not exercise either CVE or prove successful command execution. Docker isolation removes the target's default route, while Kubernetes uses egress policies whose enforcement depends on the cluster network plugin. The Kubernetes WebLogic check runs in a separate Job rather than the target's network namespace, so its connectivity result is indirect. Generated Docker publishing defaults to loopback; VM/cloud provisioning overrides it to all interfaces, with cloud ingress restricted by allowed_cidr. Kubernetes publishes TCP 7001 through a LoadBalancer and permits ingress from any IPv4 address, requiring deployment-level care. The upstream app/docker-compose.yml also publishes 7001 without the generated isolation controls. GitHub workflows validate generated artifacts, run health checks, and publish approved labs using secret-supplied backend/token endpoints; their actual addresses are unavailable. Cleanup commands in CI and VM provisioning are consistent with environment maintenance, not evidence of a fake exploit. No fixed malicious callback, credential theft, persistence, or exfiltration is present. The original analyzed repository URL, analyzed ref, and archive size were not supplied; their fields are left blank or zero rather than inferred. UPSTREAM.md separately identifies the vendored Vulhub source commit as 8fd63916f7a8711e2e01dda0d27237e4d6175d38. Analysis is static; execution success was not independently verified.
Small repository containing a write-up and a single Java proof-of-concept payload for exploiting the Oracle WebLogic Server CVE-2020-14882/CVE-2020-14883 chain. Structure is minimal: README.md provides the exploitation narrative, reconnaissance examples, vulnerable path pattern, and detection guidance; poc/exploit_payload.java contains the core payload logic. The exploit targets Oracle WebLogic Server 12.2.1.3 and uses a web attack path: first, an authentication bypass via double-encoded path traversal to /console.portal; second, code execution through a WebLogic/MVEL-related execution path. The Java payload is not a standalone program but a code fragment intended to run inside the vulnerable WebLogic execution context. It hijacks the current WebLogic worker thread, reflectively accesses the connection handler, obtains request/response objects, reads an attacker-controlled command from the X-CMD-HEADER header, executes it through cmd.exe or /bin/sh depending on the OS, captures stdout, and writes the output directly into the HTTP response stream. This gives the operator in-band command execution results rather than blind RCE. The repository is a real exploit PoC rather than a detector or fake sample, but it is operational rather than weaponized because it provides a hardcoded payload concept without a full delivery framework or customizable exploit tooling.
This repository contains a single Metasploit module targeting Oracle WebLogic Server's Administration Console for remote code execution (RCE) via a path traversal and Java class instantiation vulnerability. The exploit leverages crafted HTTP POST requests to the '/console/css/.%252e/console.portal' endpoint, abusing the 'handle' parameter to trigger code execution. It supports multiple payload types, including direct command execution and Meterpreter reverse shells, across Unix/Linux and Windows platforms. The module is weaponized, allowing for easy payload customization and automated exploitation. It targets CVE-2020-14882, CVE-2020-14883, and CVE-2020-14750, affecting WebLogic versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The code is structured as a standard Metasploit exploit module, with clear separation of check, exploit, and payload delivery logic. The only file present is the Ruby module itself, which is fully self-contained and ready for use within the Metasploit framework.
This repository contains a Python proof-of-concept exploit targeting Oracle WebLogic Server. The main file, 'weblogic.py', sends a crafted POST request to the '/console/images/%252E%252E%252Fconsole.portal' endpoint on the target server, attempting to exploit a vulnerability that allows remote code execution via the 'com.tangosol.coherence.mvel2.sh.ShellSession' class. The payload executes the 'ipconfig' command to fingerprint the operating system. The script checks the response for evidence of Windows OS and reports if the target is vulnerable. The README.md provides an example of a similar payload and a sample HTTP request. The exploit requires the attacker to specify the target's IP and port, and the target must be accessible over the network. No CVE is explicitly referenced, but the exploit is clearly aimed at WebLogic's remote code execution vulnerabilities.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Oracle WebLogic Server console vulnerability used in the article to trigger remote XML loading and validate blind-SSRF reachability.
An older Oracle WebLogic Server remote code execution vulnerability referenced as still being targeted alongside CVE-2026-21962 in attacks against WebLogic environments.
A critical Oracle WebLogic Server remote code execution flaw referenced alongside CVE-2020-14882 as part of the Console RCE issue set and observed in exploitation attempts against honeypots.
A critical Oracle WebLogic Server remote code execution vulnerability affecting the administrative console and involving authentication bypass.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.