CVE-2020-2555
Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
In plain language
AI Act nowCVE-2020-2555 is a flaw in Oracle Coherence that lets an attacker on the network take control without a login; if your business runs Oracle Coherence, you should treat it as critical and patch it now.
CVE-2020-2555 is an unauthenticated, network-triggered takeover vulnerability in Oracle Coherence (Oracle Fusion Middleware caching/invocation path); it can be exploited by attackers with network access via T3, and it is listed in the CISA KEV with an official remediation deadline.
What to do now
- Check whether you use Oracle Coherence as part of Oracle Fusion Middleware in any environment (production, staging, and test).
- Verify the exact Oracle Coherence version you run; compare it against the affected versions noted for CVE-2020-2555 (3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0).
- If any affected version is in use, upgrade/apply Oracle’s CPU fixes listed in the Oracle advisory links for CVE-2020-2555, following your vendor guidance.
- Confirm after upgrading that Oracle Coherence nodes are running the fixed update level and that the T3-facing network path is restricted as part of your exposure reduction.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2020-2555 and every CVE in our database. Create a free account — no credit card required.
Create Free Account