CVE-2020-2555
Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 91 Days)
Deserialization of Untrusted Data
DraftCommon Consequences
Applicable Platforms
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
View Exploit Code →WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
Verified Metasploit Framework (MSF)WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
View Exploit Code →Coherence by Oracle
cpe:2.3:a:oracle:coherence:3.7.1.0:*:*:*:*:*:*:*
Rapid Planning by Oracle
cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*
Retail Assortment Planning by Oracle
cpe:2.3:a:oracle:retail_assortment_planning:16.0:*:*:*:*:*:*:*
Utilities Framework by Oracle
cpe:2.3:a:oracle:utilities_framework:4.2.0.3.0:*:*:*:*:*:*:*
Healthcare Data Repository by Oracle
cpe:2.3:a:oracle:healthcare_data_repository:7.0.1:*:*:*:*:*:*:*
Commerce Platform by Oracle
cpe:2.3:a:oracle:commerce_platform:11.2.0:*:*:*:*:*:*:*
Coherence by Oracle
cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
Utilities Framework by Oracle
cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*
Utilities Framework by Oracle
cpe:2.3:a:oracle:utilities_framework:*:*:*:*:*:*:*:*
Communications Diameter Signaling Router by Oracle
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
Utilities Framework by Oracle
cpe:2.3:a:oracle:utilities_framework:4.2.0.2.0:*:*:*:*:*:*:*
Webcenter Portal by Oracle
cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
Coherence by Oracle
cpe:2.3:a:oracle:coherence:12.1.3.0.0:*:*:*:*:*:*:*
Rapid Planning by Oracle
cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*
Utilities Framework by Oracle
cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*
Access Manager by Oracle
cpe:2.3:a:oracle:access_manager:11.1.2.3.0:*:*:*:*:*:*:*
Coherence by Oracle
cpe:2.3:a:oracle:coherence:12.2.1.3.0:*:*:*:*:*:*:*
Retail Assortment Planning by Oracle
cpe:2.3:a:oracle:retail_assortment_planning:15.0:*:*:*:*:*:*:*
Webcenter Portal by Oracle
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
Commerce Platform by Oracle
cpe:2.3:a:oracle:commerce_platform:11.0.0:*:*:*:*:*:*:*
Commerce Platform by Oracle
cpe:2.3:a:oracle:commerce_platform:*:*:*:*:*:*:*:*
Commerce Platform by Oracle
cpe:2.3:a:oracle:commerce_platform:11.1.0:*:*:*:*:*:*:*