Back

CVE-2020-2555

CRITICAL CISA KEV

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Published: Jan 15, 2020 Modified: Jun 17, 2026
CWE-502 CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (22)

Vendor Product Version
oracle access_manager 11.1.2.3.0
oracle coherence 3.7.1.0
oracle coherence 12.1.3.0.0
oracle coherence 12.2.1.3.0
oracle coherence 12.2.1.4.0
oracle commerce_platform * ≥ 11.3.0
oracle commerce_platform 11.0.0
oracle commerce_platform 11.1.0
oracle commerce_platform 11.2.0
oracle communications_diameter_signaling_router * ≥ 8.0.0
oracle healthcare_data_repository 7.0.1
oracle rapid_planning 12.1
oracle rapid_planning 12.2
oracle retail_assortment_planning 15.0
oracle retail_assortment_planning 16.0
oracle utilities_framework * ≥ 4.3.0.1.0
oracle utilities_framework 4.2.0.2.0
oracle utilities_framework 4.2.0.3.0
oracle utilities_framework 4.4.0.0.0
oracle utilities_framework 4.4.0.2.0

…and 2 more

GitHub Security Advisory GHSA-gm93-pfh3-mrf3

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching...

References (17)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 97.12%

Top 0% most likely to be exploited

Threat Score 98.3 / 100

CISA Known Exploited

Date Added: 2021-11-03
Due Date: 2022-05-03
Required Action:

Apply updates per vendor instructions.

Data Sources

NVD CISA KEV EPSS GitHub