vendor:
WebLogic Server
by:
nu11secur1ty
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: WebLogic Server
Affected Version From: 12.2.1.4.0
Affected Version To: 12.2.1.4.0
Patch Exists: YES
Related CWE: CVE-2020-2555
CPE: a:oracle:weblogic_server:12.2.1.4.0
Platforms Tested:
2020
Oracle WebLogic Server 12.2.1.4.0 – Remote Code Execution
This exploit allows remote code execution in Oracle WebLogic Server 12.2.1.4.0. The exploit code is written in Python and connects to a specified host and port. It sends headers to the server and then sends a payload to execute the code.
Mitigation:
Apply the necessary patches and updates provided by Oracle. Restrict network access to the affected system.