CVE-2020-2555 is a critical deserialization vulnerability in Oracle Coherence, affecting versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0, as well as several other Oracle Fusion Middleware products. This easily exploitable flaw allows an unauthenticated attacker with network access via T3 to achieve complete takeover of the affected Oracle Coherence instance, leading to full confidentiality, integrity, and availability compromise. With a CVSS v3.0 score of 9.8 (Critical), it is actively exploited in the wild, with public exploit code available, including Metasploit modules and ExploitDB entries. The vulnerability has garnered significant community discussion and media coverage, notably being listed by the NSA as actively abused by Chinese state-sponsored hackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:access_manager:11.1.2.3.0:*:*:*:*:*:*:* | ||
3.7.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:coherence:3.7.1.0:*:*:*:*:*:*:* | ||
12.1.3.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:coherence:12.1.3.0.0:*:*:*:*:*:*:* | ||
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:coherence:12.2.1.3.0:*:*:*:*:*:*:* | ||
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.