cbcvebase.
CVE-2020-14883
published 2020-10-21

CVE-2020-14883: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0…

PriorityP187high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
97.93%
99.9th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Affected

10 ranges
VendorProductVersion rangeFixed in
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracleweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server
oracle_corporationweblogic_server

Detection & IOCsextracted from sources · hover to see the quote

hash61879d5b2f083b69e8e6cc6afce00be6619176151b093de14f2778a87ea46565
hash6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b
hashdd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839
urlhxxp://194[.]38[.]20[.]199/wb.sh
urlhxxp://194[.]38[.]20[.]199/kinsing
filenamewb.xml
filenamekdevtmpfsi
  • IPS rule 1010590 detects and blocks exploitation of CVE-2020-14882, CVE-2020-14750, and CVE-2020-14883 on Oracle WebLogic Server
  • IPS rule 1004090 detects directory traversal sequences in URI, relevant to the double URL-encoded traversal used in CVE-2020-14883 exploitation
  • Post-exploitation activity includes Java process spawning a bash shell — monitor for Java processes opening bash shells as an indicator of WebLogic exploitation
  • ·The Kinsing wb.sh stager checks for /tmp/zzza before executing; manually creating this file can prevent the stager from running further actions on a host, but this is not a substitute for patching
  • ·IPS rule 1010590 covers CVE-2020-14882, CVE-2020-14750, AND CVE-2020-14883 together — triggering on this rule does not isolate which specific CVE is being exploited

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck7.2HIGH
cisa7.2HIGH
vendor_oracle7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.