Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2020-2555 | First vendor Publication | 2020-01-15 |
Vendor | Cve | Last vendor Modification | 2025-02-14 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 9.8 | ||
Base Score | 9.8 | Environmental Score | 9.8 |
impact SubScore | 5.9 | Temporal Score | 9.8 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2555 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-502 | Deserialization of Untrusted Data |
CPE : Common Platform Enumeration
SAINT Exploits
Description | Link |
---|---|
Oracle WebLogic Server BadAttributeValueExpException deserialization | More info here |
Snort® IPS/IDS
Date | Description |
---|---|
2020-05-27 | Oracle Coherence library LimitFilter insecure deserialization attempt RuleID : 53744 - Revision : 1 - Type : SERVER-ORACLE |
Metasploit Database
id | Description |
---|---|
2020-01-15 | WebLogic Server Deserialization RCE - BadAttributeValueExpException |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-14 21:21:55 |
|
2024-11-28 13:42:26 |
|
2024-10-02 21:28:03 |
|
2024-09-30 21:27:48 |
|
2022-11-10 12:51:59 |
|
2022-10-25 21:27:39 |
|
2022-07-13 17:27:57 |
|
2022-02-17 01:47:08 |
|
2021-08-05 01:38:12 |
|
2021-07-21 05:23:07 |
|
2021-05-04 13:50:52 |
|
2021-04-22 03:02:35 |
|
2021-03-26 12:34:00 |
|
2021-01-20 21:23:24 |
|
2020-10-21 21:23:36 |
|
2020-07-16 00:22:55 |
|
2020-05-29 21:22:56 |
|
2020-05-27 21:22:49 |
|
2020-05-23 13:17:11 |
|
2020-05-23 02:36:11 |
|