CVE-2020-2555
KEV PoC ×3largeUnauthenticated deserialization RCE in Oracle Coherence via T3
CISA: Oracle Multiple Products Remote Code Execution Vulnerability
Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 contain a deserialization flaw (CWE-502) in the Caching, CacheStore and Invocation components, rated 9.8 (critical). An unauthenticated attacker with network access to the T3 protocol — the listener typically exposed by Oracle WebLogic Server, which bundles Coherence — can send a crafted serialized payload and take over Coherence, effectively achieving remote code execution in the hosting Java process with no credentials or user interaction required. Beyond standalone Coherence, the flaw affects the Oracle Fusion Middleware products that bundle it, including Access Manager, WebCenter Portal, Commerce Platform, Rapid Planning and others. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03, EPSS estimates a ~97% probability of exploitation within 30 days, public PoCs and exploit write-ups exist, and related reporting flags it among vulnerabilities heavily used by Chinese state-sponsored hackers.
What to do: Apply the Coherence fixes from Oracle's January 2020 Critical Patch Update (or later) for Coherence 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0 and for every listed product that embeds Coherence, prioritizing WebLogic-based deployments given active exploitation and the 9.8 CVSS. Until patched, restrict T3/T3S access to trusted networks and remove direct internet exposure of WebLogic listener ports, and keep this in your KEV/EPSS-driven remediation queue; hunt for unexpected code execution or outbound connections originating from T3 listeners.
| Oracle Coherence | 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 (Caching, CacheStore, Invocation components) |
| Oracle Access Manager | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Commerce Platform | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Communications Diameter Signaling Router | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Healthcare Data Repository | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Rapid Planning | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Retail Assortment Planning | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle Utilities Framework | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
| Oracle WebCenter Portal | affected via bundled Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3.0/12.2.1.4.0; product-level version ranges not specified in source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Affected
- Oracle Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- access manager, coherence, commerce platform, communications diameter signaling router, healthcare data repository, rapid planning, retail assortment planning, utilities framework, webcenter portal
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H