CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2020-2555

CVSS 9.8v3.1pub. 2020-01-15upd. 2025-10-27

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Oracle Access Manager

    APP
    Oracle
    11.1.2.3.0
  • Oracle Coherence

    APP
    Oracle
    12.1.3.0.012.2.1.3.012.2.1.4.03.7.1.0
  • Oracle Commerce Platform

    APP
    Oracle
    11.0.011.1.011.2.011.3.0 – 11.3.2
  • Oracle Communications Diameter Signaling Router

    APP
    Oracle
    8.0.0 – 8.2.2
  • Oracle Healthcare Data Repository

    APP
    Oracle
    7.0.1
  • Oracle Rapid Planning

    APP
    Oracle
    12.112.2
  • Oracle Retail Assortment Planning

    APP
    Oracle
    15.016.0
  • Oracle Utilities Framework

    APP
    Oracle
    4.2.0.2.04.2.0.3.04.4.0.0.04.4.0.2.04.3.0.1.0 – 4.3.0.6.0
  • Oracle Webcenter Portal

    APP
    Oracle
    12.2.1.3.012.2.1.4.0

CISA KEV — detailsi

Vendori
Oracle
Producti
Multiple Products
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 maja 2022
Tags
Auth BypassDoSDeserialization
CWE
References

Related vulnerabilities

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2021-35587CRITICAL9.8⚠ KEVPL ✓same product

Krytyczny Auth Bypass w Oracle Access Manager — przejęcie systemu

CVE-2017-9841CRITICAL9.8⚠ KEVPL ✓same product

RCE w PHPUnit — wykonanie kodu PHP przez eval-stdin.php

CVE-2026-60728CRITICAL9.1same product

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services)...

CVE-2026-60730CRITICAL9.9same product

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Suppo...