ZeroHour

CVE-2020-2555

KEV PoC ×3large

Unauthenticated deserialization RCE in Oracle Coherence via T3

CISA: Oracle Multiple Products Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 contain a deserialization flaw (CWE-502) in the Caching, CacheStore and Invocation components, rated 9.8 (critical). An unauthenticated attacker with network access to the T3 protocol — the listener typically exposed by Oracle WebLogic Server, which bundles Coherence — can send a crafted serialized payload and take over Coherence, effectively achieving remote code execution in the hosting Java process with no credentials or user interaction required. Beyond standalone Coherence, the flaw affects the Oracle Fusion Middleware products that bundle it, including Access Manager, WebCenter Portal, Commerce Platform, Rapid Planning and others. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03, EPSS estimates a ~97% probability of exploitation within 30 days, public PoCs and exploit write-ups exist, and related reporting flags it among vulnerabilities heavily used by Chinese state-sponsored hackers.

What to do: Apply the Coherence fixes from Oracle's January 2020 Critical Patch Update (or later) for Coherence 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 and for every listed product that embeds Coherence, prioritizing WebLogic-based deployments given active exploitation and the 9.8 CVSS. Until patched, restrict T3/T3S access to trusted networks and remove direct internet exposure of WebLogic listener ports, and keep this in your KEV/EPSS-driven remediation queue; hunt for unexpected code execution or outbound connections originating from T3 listeners.

Affected
Oracle Coherence3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 (Caching, CacheStore, Invocation components)
Oracle Access Manageraffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Commerce Platformaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Communications Diameter Signaling Routeraffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Healthcare Data Repositoryaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Rapid Planningaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Retail Assortment Planningaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle Utilities Frameworkaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Oracle WebCenter Portalaffected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data
Estimated exposure
largetens of thousands of internet-exposed Oracle WebLogic/Coherence T3 servers (public scans show on the order of 10,000–50,000); total enterprise install base… — Coherence ships embedded in Oracle WebLogic Server and the listed Fusion Middleware products, and public internet scans (Shodan/Censys) have consistently shown tens of thousands of exposed WebLogic T3 endpoints, with additional unexposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CISA Known Exploited Vulnerability
Affected
Oracle Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
access manager, coherence, commerce platform, communications diameter signaling router, healthcare data repository, rapid planning, retail assortment planning, utilities framework, webcenter portal
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news