CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 97.1% chance of exploitation in the next 30 days.
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected products
- Oracle Access Manager: version 11.1.2.3.0 only
- Oracle Coherence: version 3.7.1.0 only; version 12.1.3.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Commerce Platform: from 11.3.0, up to and including 11.3.2; version 11.0.0 only; version 11.1.0 only; version 11.2.0 only
- Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
- Oracle Healthcare Data Repository: version 7.0.1 only
- Oracle Rapid Planning: version 12.1 only; version 12.2 only
- Oracle Retail Assortment Planning: version 15.0 only; version 16.0 only
- Oracle Utilities Framework: from 4.3.0.1.0, up to and including 4.3.0.6.0; version 4.2.0.2.0 only; version 4.2.0.3.0 only; version 4.4.0.0.0 only; version 4.4.0.2.0 only
- Oracle Webcenter Portal: version 12.2.1.3.0 only; version 12.2.1.4.0 only
Published 2020-01-15. Last modified 2026-06-17.