EXPOSURES › CVE-2020-2555
CVE-2020-2555
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP.
An unauthenticated attacker could exploit this RCE vulnerability to gain full control of affected Oracle systems, leading to potential data breaches, ransomware deployment, or lateral movement. DIB organizations must ensure all Oracle products are patched immediately, as this flaw was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for systems handling CUI.
Shame score — The vulnerability was unauthenticated, actively exploited in the wild, and affected multiple Oracle products, indicating a severe and avoidable failure in Oracle's patch management and security posture.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR).
"Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |