PT-2020-1544 · Oracle · Oracle Coherence
Published
2020-01-14
·
Updated
2025-04-18
·
CVE-2020-2555
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0
Description
The issue is related to insufficient access control in the Caching, CacheStore, Invocation component of Oracle Coherence, allowing an unauthenticated attacker with network access via the T3 protocol to compromise Oracle Coherence. Successful attacks can result in the takeover of Oracle Coherence.
Recommendations
For versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, consider disabling the T3 protocol until a patch is available to prevent exploitation.
Restrict access to the Caching, CacheStore, Invocation component to minimize the risk of exploitation.
Avoid using the T3 protocol in the affected Oracle Coherence versions until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Coherence