PT-2020-1544 · Oracle · Oracle Coherence

Published

2020-01-14

·

Updated

2025-04-18

·

CVE-2020-2555

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0
Description The issue is related to insufficient access control in the Caching, CacheStore, Invocation component of Oracle Coherence, allowing an unauthenticated attacker with network access via the T3 protocol to compromise Oracle Coherence. Successful attacks can result in the takeover of Oracle Coherence.
Recommendations For versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, consider disabling the T3 protocol until a patch is available to prevent exploitation. Restrict access to the Caching, CacheStore, Invocation component to minimize the risk of exploitation. Avoid using the T3 protocol in the affected Oracle Coherence versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2020-00538
CVE-2020-2555
ORACLEWEBLOGIC_CVE2020_2555
ZDI-20-128

Affected Products

Oracle Coherence