9.8

CVE-2020-2555

Warnung
Exploit
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Access Manager Version 11.1.2.3.0
Oracle ≫ Coherence Version 3.7.1.0
Oracle ≫ Coherence Version 12.1.3.0.0
Oracle ≫ Coherence Version 12.2.1.3.0
Oracle ≫ Coherence Version 12.2.1.4.0
Oracle ≫ Commerce Platform Version >= 11.3.0 <= 11.3.2
Oracle ≫ Commerce Platform Version 11.0.0
Oracle ≫ Commerce Platform Version 11.1.0
Oracle ≫ Commerce Platform Version 11.2.0
Oracle ≫ Communications Diameter Signaling Router Version >= 8.0.0 <= 8.2.2
Oracle ≫ Rapid Planning Version 12.1
Oracle ≫ Rapid Planning Version 12.2
Oracle ≫ Utilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
Oracle ≫ Utilities Framework Version 4.2.0.2.0
Oracle ≫ Utilities Framework Version 4.2.0.3.0
Oracle ≫ Utilities Framework Version 4.4.0.0.0
Oracle ≫ Utilities Framework Version 4.4.0.2.0
Oracle ≫ Webcenter Portal Version 12.2.1.3.0
Oracle ≫ Webcenter Portal Version 12.2.1.4.0

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Multiple Products Remote Code Execution Vulnerability

Schwachstelle

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.12% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Oracle 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.oracle.com/security-alerts/cpujan2020.html
Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2020.html
Vendor Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2021.html
Patch
Vendor Advisory
http://packetstormsecurity.com/files/157054/Oracle-Coherence-Fusion-Middleware-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/157207/Oracle-WebLogic-Server-12.2.1.4.0-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
http://packetstormsecurity.com/files/157795/WebLogic-Server-Deserialization-Remote-Code-Execution.html
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-2555
US Government Resource