CVE-2020-14882
WebLogic Console RCE (2020): stopped at runtime
Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.
Published October 21, 2020 · Updated May 26, 2026
The vulnerability
Remote code execution via Administration Console access-control bypass
A crafted URL path lets an unauthenticated attacker bypass the access controls protecting WebLogic's Administration Console, reaching internal console handlers that were never meant to be exposed. Combined with a follow-on request, this grants full unauthenticated remote code execution and has been mass-exploited in the wild.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| WebLogic Console RCE (2020) protectionCVE-2020-14882 · Authentication bypass leading to remote code execution | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
WebLogic Console RCE (2020) FAQ
Is WebLogic Console RCE (2020) (CVE-2020-14882) exploitable?
CVE-2020-14882 carries a CVSS 9.8/10 (CRITICAL) rating and affects Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0. A crafted URL path lets an unauthenticated attacker bypass the access controls protecting WebLogic's Administration Console, reaching internal console handlers that were never meant to be exposed. Combined with a follow-on request, this grants full unauthenticated remote code execution and has been mass-exploited in the wild. It is listed in CISA's Known Exploited Vulnerabilities catalog.
How does Waratek mitigate WebLogic Console RCE (2020) (CVE-2020-14882)?
Waratek RASP blocks exploitation of WebLogic Console RCE (2020) (CVE-2020-14882) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
How quickly was WebLogic Console RCE (2020) (CVE-2020-14882) exploited after disclosure?
Exploit code for CVE-2020-14882 was already circulating publicly on April 1, 2020, before the vulnerability was even formally published in the NVD. Attackers had a head start before most defenders had a CVE record to react to.
Protect your apps in production
Get protected against WebLogic Console RCE (2020) - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2020-14882 and attacks like it, and get you covered in production.