CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Other sources
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Coherence (Fusion Middleware)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle Coherence (Fusion Middleware)to a version that resolves this vulnerability.Fixed in 12.2.1.3.0 - Upgrade
Upgrade
Oracle Coherence (Fusion Middleware)to a version that resolves this vulnerability.Fixed in 12.1.3.0.0 - Upgrade
Upgrade
Oracle Coherence (Fusion Middleware)to a version that resolves this vulnerability.Fixed in 3.7.1.0 - Compensating control
Restrict network access to Oracle Coherence using the T3 and HTTP interfaces so unauthenticated attackers cannot reach the affected service (component: Caching/CacheStore/Invocation).
Event History
Frequently Asked Questions
What is CVE-2020-2555?
CVE-2020-2555 is a remote code execution vulnerability in the Oracle Coherence product of Oracle Fusion Middleware.
Which Oracle products are affected by CVE-2020-2555?
Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0 are affected.
What is the severity of CVE-2020-2555?
CVE-2020-2555 has a severity rating of 9.8, which is classified as critical.
How can the CVE-2020-2555 vulnerability be exploited?
The vulnerability can be exploited by an unauthenticated attacker with network access via T3 protocol.
Are there any references or sources of more information about CVE-2020-2555?
Yes, you can find more information about CVE-2020-2555 at the following links: [Link 1](http://packetstormsecurity.com/files/157054/Oracle-Coherence-Fusion-Middleware-Remote-Code-Execution.html), [Link 2](http://packetstormsecurity.com/files/157207/Oracle-WebLogic-Server-12.2.1.4.0-Remote-Code-Execution.html), [Link 3](http://packetstormsecurity.com/files/157795/WebLogic-Server-Deserialization-Remote-Code-Execution.html).