Skip to main content

CVE-2020-14750

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Oracle
Severity: CRITICAL
CVE ID: CVE-2020-14750
CVSS Score: 9.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Refrence: NVDMITRE

Proof Of Concept

Nuclei Templates for CVE-2020-14750
pprietosanchez

PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882

Refrence: GitHub

kkhacklabs

Refrence: GitHub

Content on GitHub

0xn0ne | watchers:1930

weblogicScanner
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-3252、CVE-2019-2618、CVE-2019-2725、CVE-2019-2729、CVE-2019-2890、CVE-2020-2551、CVE-2020-14750、CVE-2020-14882、CVE-2020-14883

Refrence: GitHub

NS-Sp4ce | watchers:20

CVE-2020-14882
CVE-2020-14882/14883/14750

Refrence: GitHub

corelight | watchers:7

CVE-2020-14882-weblogicRCE
Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

Refrence: GitHub