LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-2555: Oracle Multiple Products Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-2555 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle…

CVE-2020-2555 is a remote code execution vulnerability affecting multiple Oracle products. An unauthenticated attacker with network access over T3 or HTTP can take over the affected system. Impacted products named in public reporting include Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, and Oracle Communications Diameter Signaling Router (DSR). Because successful exploitation can lead to full system control, IT and security teams should treat exposed instances as high priority for inventory and remediation. Confirm exact product lists, versions, and fixed releases against the vendor advisory.

How it works

The underlying weakness is CWE-502: deserialization of untrusted data. In products that accept serialized objects over network protocols such as T3 or HTTP, an attacker who can reach the service may supply a crafted payload. When the application deserializes that data without adequate validation, the payload can trigger unintended code execution in the context of the vulnerable process. Public descriptions state that no authentication is required and that network access via T3 or HTTP is sufficient for takeover of the affected system. Specific exploit mechanics, gadget chains, or payload formats are not detailed here; defenders should rely on the vendor advisory and their own testing rather than assuming any particular technique.

Am I affected? How to find it in your systems

These Oracle components commonly appear in middleware, retail, utilities, commerce, and telecommunications environments. Oracle Coherence is often embedded in Fusion Middleware deployments; the other named products may run as standalone or integrated application tiers. Practical discovery steps include:

If you cannot determine whether a given Oracle installation includes an affected component, treat it as potentially in scope until the vendor documentation or Oracle support confirms otherwise.

How to remediate

Patching is the primary remediation. Apply the updates Oracle has issued for the affected products, following the vendor instructions referenced by CISA and the official security advisory. After installing fixes:

Document the change window and retain evidence of the applied updates for audit and incident-response purposes.

If you can't patch immediately

Until patches can be deployed, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule patching as soon as operationally possible.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities can lead to system takeover and subsequent data theft or ransomware deployment; public reporting for this CVE does not document known ransomware use. If you discover that vulnerable instances were internet-facing or otherwise reachable by untrusted parties before patching, initiate your incident-response process: isolate hosts, preserve logs and memory where appropriate, and assess whether credentials, application data, or downstream systems were accessed. As a routine hygiene step, users and administrators can run a free exposure scan of their email addresses against known breach datasets to check for previously compromised credentials that might be reused in follow-on attacks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · Multiple Products
WeaknessCWE-502
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities