Improper input validation in Oracle Coherence - CVE-2020-2555
Published: February 7, 2020 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Caching,CacheStore,Invocation component in Oracle Coherence. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Utilities Framework
Oracle Healthcare Data Repository
Integrated Diameter Intelligence Hub (IDIH)
Oracle Commerce Platform
Oracle Access Manager
Oracle WebCenter Portal
How to mitigate CVE-2020-2555
Links to Public Exploits and PoC-codes
- Exploit #7021 - POC_CVE-2020-2555 (poc for CVE-2020-2555) (November 16, 2021)
- Exploit #5728 - Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution (June 17, 2021)
- Exploit #5397 - CodeTest (CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。) (May 12, 2021)
- Exploit #5231 - Attacking_Shiro_with_CVE_2020_2555 () (March 22, 2021)
- Exploit #4640 - CVE-2020-2555 () (September 21, 2020)
- Exploit #2964 - CVE-2020-2883 (Weblogic coherence.jar RCE) (June 3, 2020)
- Exploit #2978 - weblogicPoc (Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。) (June 3, 2020)
- Exploit #2778 - WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit) (May 24, 2020)
- Exploit #2777 - WebLogic Server Deserialization RCE - BadAttributeValueExpException (May 21, 2020)
- Exploit #2256 - cve-2020-2555 (CVE-2020-2555) (April 3, 2020)
- Exploit #296 - CVE-2020-2555 () (March 18, 2020)
- Exploit #297 - CVE-2020-2555 (Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE) (March 18, 2020)
- Exploit #298 - CVE-2020-2555 (CVE-2020-2555 Python POC) (March 18, 2020)
- Exploit #299 - CVE-2020-2555 (CVE-2020-2555) (March 18, 2020)
External References
Related Security Bulletins
- Improper input validation in Oracle Coherence
- Multiple vulnerabilities in Integrated Diameter Intelligence Hub (IDIH)
- Improper input validation in Oracle Healthcare Data Repository
- Multiple vulnerabilities in Oracle WebCenter Portal
- Improper input validation in Oracle Utilities Framework
- Multiple vulnerabilities in Oracle Commerce Platform
- Multiple vulnerabilities in Oracle Access Manager