Oracle WebLogic Authentication Bypass (CVE-2020-14883)

Severity: High

Invicti identified the Oracle WebLogic Authentication Bypass (CVE-2020-14883) in the target web server.


An attacker can bypass authentication and gain access to the vulnerable WebLogic instance. Due to the high privileges acquired, an attacker can carry out any administrative action and take complete control over the application.

Exploit of the vulnerability is known widely and should be addressed as soon as possible.


In order to patch this vulnerability, please install the official patch Oracle made available for supported, vulnerable instances.

Invicti Logo

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo