Junglewise Threat Intelligence

CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability

CVE-2020-2555 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Oracle Coherence, Oracle Commerce Platform, Oracle WebCenter Portal. Vendors: Oracle.

Executive brief

A deserialization of untrusted data vulnerability in Oracle Coherence and multiple other Oracle products allows an unauthenticated attacker with network access via the T3 or HTTP protocols to execute arbitrary code. Successful exploitation can lead to a complete takeover of the affected system.

Affected products

  • Oracle Coherence 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
  • Oracle Utilities Framework 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0
  • Oracle Retail Assortment Planning 15.0, 16.0
  • Oracle Commerce Platform 11.0.0, 11.1.0, 11.2.0, 11.3.0 - 11.3.2
  • Oracle Communications Diameter Signaling Router (DSR) 8.0.0 - 8.2.2
  • Oracle WebCenter Portal 12.2.1.3.0, 12.2.1.4.0

Timeline

  • 2020-01-15: advisory: Initial Oracle Critical Patch Update (CPU) advisory published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed