Improper input validation in Oracle Coherence - CVE-2020-2555

 

Improper input validation in Oracle Coherence - CVE-2020-2555

Published: February 7, 2020 / Updated: February 20, 2022


Vulnerability identifier: #VU25048
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2555
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Caching,CacheStore,Invocation component in Oracle Coherence. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Coherence
Oracle Utilities Framework
Oracle Healthcare Data Repository
Integrated Diameter Intelligence Hub (IDIH)
Oracle Commerce Platform
Oracle Access Manager
Oracle WebCenter Portal

How to mitigate CVE-2020-2555

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins