CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-2555

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score35.3540%
EPSS Percentile85.09th
Published2020年1月15日
Last Modified2025年10月27日

Vulnerability Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Platforms (CPE)

📦
Oracle

Access Manager

= 11.1.2.3.0
📦
Oracle

Coherence

= 3.7.1.0
📦
Oracle

Coherence

= 12.1.3.0.0
📦
Oracle

Coherence

= 12.2.1.3.0
📦
Oracle

Coherence

= 12.2.1.4.0
📦
Oracle

Commerce Platform

>= 11.3.0 and <= 11.3.2
📦
Oracle

Commerce Platform

= 11.0.0
📦
Oracle

Commerce Platform

= 11.1.0
📦
Oracle

Commerce Platform

= 11.2.0
📦
Oracle

Communications Diameter Signaling Router

>= 8.0.0 and <= 8.2.2
📦
Oracle

Healthcare Data Repository

= 7.0.1
📦
Oracle

Rapid Planning

= 12.1
📦
Oracle

Rapid Planning

= 12.2
📦
Oracle

Retail Assortment Planning

= 15.0
📦
Oracle

Retail Assortment Planning

= 16.0
📦
Oracle

Utilities Framework

>= 4.3.0.1.0 and <= 4.3.0.6.0
📦
Oracle

Utilities Framework

= 4.2.0.2.0
📦
Oracle

Utilities Framework

= 4.2.0.3.0
📦
Oracle

Utilities Framework

= 4.4.0.0.0
📦
Oracle

Utilities Framework

= 4.4.0.2.0
📦
Oracle

Webcenter Portal

= 12.2.1.3.0
📦
Oracle

Webcenter Portal

= 12.2.1.4.0

References & Advisories

相關漏洞威脅