CVE-2020-14756: Critical severity oracle coherence vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14756?
The severity of CVE-2020-14756 is critical with a CVSS score of 9.8.
Which versions of Oracle Coherence are affected by CVE-2020-14756?
The affected versions of Oracle Coherence are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.
How can CVE-2020-14756 be exploited?
CVE-2020-14756 can be exploited by an unauthenticated attacker with network access via IIOP.
What is the affected component of Oracle Fusion Middleware?
The affected component of Oracle Fusion Middleware is Core Components.
How can I fix CVE-2020-14756?
To fix CVE-2020-14756, it is recommended to apply the necessary patches provided by Oracle Fusion Middleware.