CVE-2020-2555criticalunder attackCWE-502

CVE-2020-2555: critical vulnerability in Oracle Corporation Utilities Framework

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 97%
from disclosure to weapon0 days
Published on NVDJan 15
1st PoCJan 15
metasploitJan 15
CISA KEV+658d
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
17 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Oracle Coherence contains a critical flaw allowing attackers to remotely take over the system without any authentication. An attacker can send specially crafted data through the network to execute malicious code and gain complete control.

Technical detail

Unsafe deserialization vulnerability (CWE-502) in Oracle Coherence caching component accessible via T3 protocol. Requires network access but no authentication or user interaction; successful exploitation results in remote code execution and complete system compromise affecting versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.