Skip to content
COOEY

EXPOSURES › CVE-2020-2555

CVE-2020-2555

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-2555 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP.

An unauthenticated attacker could exploit this RCE vulnerability to gain full control of affected Oracle systems, leading to potential data breaches, ransomware deployment, or lateral movement. DIB organizations must ensure all Oracle products are patched immediately, as this flaw was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for systems handling CUI.

Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and affected multiple Oracle products, indicating a severe and avoidable failure in Oracle's patch management and security posture.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Oracle faced severe criticism for a critical RCE vulnerability affecting multiple products, allowing unauthenticated attackers to take over systems.
cooey ↗ severe-fallout -0.60
Oracle faced severe criticism for a critical RCE vulnerability affecting multiple products, allowing unauthenticated attackers to take over systems.
"Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system."
AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized