
结合14882的未授权访问漏洞,通过14883可远程执行任意代码
WebLogic is a J2EE application server launched by Oracle.
CVE-2020-14882 is an unauthorized access vulnerability in the Console, with a severity rating ofCriticaland a CVSS score of9.8. Meanwhile,CVE-2020-14883 is a code execution vulnerability in the Console that exploits the unauthorized access. As a result, remote attackers can craft special HTTP requests to take over the WebLogic Server Console without authentication and execute arbitrary code in the WebLogic Server Console.