peter bassill · operator
$ cve CVE-2020-2555 JSON

CVE-2020-2555 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 97.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.12% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2020-01-15
Last modified2026-06-17

CISA KEV

NameOracle Multiple Products Remote Code Execution Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productOracle / Multiple Products
Ransomware usenone reported

Affected (9)

VendorProduct
oracleaccess manager
oraclecoherence
oraclecommerce platform
oraclecommunications diameter signaling router
oraclehealthcare data repository
oraclerapid planning
oracleretail assortment planning
oracleutilities framework
oraclewebcenter portal

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD