CVE-2020-2555 vulnerability in Oracle Products
Published on January 15, 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Known Exploited Vulnerability
This Oracle Coherence Deserialization Remote Code Execution vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence.
The following remediation steps are recommended / required by May 3, 2022: Apply updates per vendor instructions.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2020-2555 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2020-2555
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-2555 are published in these products:
Affected Versions
Oracle Corporation WebCenter Portal:- Version 12.2.1.3.0 is affected.
- Version 12.2.1.4.0 is affected.
- Version 4.2.0.2.0 is affected.
- Version 4.2.0.3.0 is affected.
- Version 4.3.0.1.0-4.3.0.6.0 is affected.
- Version 4.4.0.0.0 is affected.
- Version 4.4.0.2.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.