Executive brief
A deserialization of untrusted data vulnerability in Oracle Coherence and multiple other Oracle products allows an unauthenticated attacker with network access via the T3 or HTTP protocols to execute arbitrary code. Successful exploitation can lead to a complete takeover of the affected system.
Affected products
- Oracle Coherence 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
- Oracle Utilities Framework 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0
- Oracle Retail Assortment Planning 15.0, 16.0
- Oracle Commerce Platform 11.0.0, 11.1.0, 11.2.0, 11.3.0 - 11.3.2
- Oracle Communications Diameter Signaling Router (DSR) 8.0.0 - 8.2.2
- Oracle WebCenter Portal 12.2.1.3.0, 12.2.1.4.0
Timeline
- 2020-01-15: advisory: Initial Oracle Critical Patch Update (CPU) advisory published
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: disclosed