CyberSec.Space Logo
Back to CVE Browser

CVE-2020-2555

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score35.3540%
EPSS Percentile85.09th
PublishedJan 15, 2020
Last ModifiedOct 27, 2025

Vulnerability Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Platforms (CPE)

πŸ“¦
Oracle

Access Manager

= 11.1.2.3.0
πŸ“¦
Oracle

Coherence

= 3.7.1.0
πŸ“¦
Oracle

Coherence

= 12.1.3.0.0
πŸ“¦
Oracle

Coherence

= 12.2.1.3.0
πŸ“¦
Oracle

Coherence

= 12.2.1.4.0
πŸ“¦
Oracle

Commerce Platform

>= 11.3.0 and <= 11.3.2
πŸ“¦
Oracle

Commerce Platform

= 11.0.0
πŸ“¦
Oracle

Commerce Platform

= 11.1.0
πŸ“¦
Oracle

Commerce Platform

= 11.2.0
πŸ“¦
Oracle

Communications Diameter Signaling Router

>= 8.0.0 and <= 8.2.2
πŸ“¦
Oracle

Healthcare Data Repository

= 7.0.1
πŸ“¦
Oracle

Rapid Planning

= 12.1
πŸ“¦
Oracle

Rapid Planning

= 12.2
πŸ“¦
Oracle

Retail Assortment Planning

= 15.0
πŸ“¦
Oracle

Retail Assortment Planning

= 16.0
πŸ“¦
Oracle

Utilities Framework

>= 4.3.0.1.0 and <= 4.3.0.6.0
πŸ“¦
Oracle

Utilities Framework

= 4.2.0.2.0
πŸ“¦
Oracle

Utilities Framework

= 4.2.0.3.0
πŸ“¦
Oracle

Utilities Framework

= 4.4.0.0.0
πŸ“¦
Oracle

Utilities Framework

= 4.4.0.2.0
πŸ“¦
Oracle

Webcenter Portal

= 12.2.1.3.0
πŸ“¦
Oracle

Webcenter Portal

= 12.2.1.4.0

References & Advisories

Related Vulnerabilities