CVE-2020-14756
published 2021-01-20CVE-2020-14756: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
74.75%
99.4th percentile
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | coherence | — | — |
| oracle | coherence | — | — |
| oracle | coherence | — | — |
| oracle | coherence | — | — |
| oracle | coherence | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | — | — |
| oracle | utilities_framework | 4.3.0.1.0 – 4.3.0.6.0 | — |
| oracle_corporation | utilities_framework | — | — |
| oracle_corporation | utilities_framework | — | — |
| oracle_corporation | utilities_framework | — | — |
| oracle_corporation | utilities_framework | — | — |
| oracle_corporation | utilities_framework | — | — |
| oracle_corporation | utilities_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated inbound connections over IIOP and T3 protocols targeting Oracle Coherence, as these are the attack vectors for CVE-2020-14756 ↗
- →Detect Java deserialization gadget chain exploitation attempts delivered over T3/IIOP to Oracle Coherence Core Components ↗
- ·CVE-2020-14756 affects Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0; detections should be scoped to these versions ↗
- ·The vulnerability is exploitable remotely with no authentication and no user interaction required (CVSS 9.8), meaning any network-accessible Coherence instance is at risk without additional prerequisites ↗
- ·Attack surface includes both IIOP and T3 protocols; blocking or restricting both protocols at the network perimeter is necessary to reduce exposure ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Utilities Applications Risk Matrix: General (Oracle Coherence) — CVE-2020-14756
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2020-14756 [CRITICAL] Oracle Oracle Utilities Applications Risk Matrix: General (Oracle Coherence) — CVE-2020-14756
Oracle Oracle Utilities Applications Risk Matrix: General (Oracle Coherence) vulnerability
CVE: CVE-2020-14756
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Core Components — CVE-2020-14756
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-14756 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Core Components — CVE-2020-14756
Oracle Oracle Fusion Middleware Risk Matrix: Core Components vulnerability
CVE: CVE-2020-14756
CVSS: 9.8
Protocol: IIOP, T3
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
GHSA
GHSA-p7pp-gqpg-99cg: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components)
ghsa_unreviewed·2022-05-24
CVE-2020-14756 [CRITICAL] GHSA-p7pp-gqpg-99cg: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components)
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle Coherence Product of Oracle Fusion Middleware Core Components IIOP/T3 Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-14756 [CRITICAL] Oracle Coherence Product of Oracle Fusion Middleware Core Components IIOP/T3 Vulnerability
Oracle Coherence Product of Oracle Fusion Middleware Core Components IIOP/T3 Vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected: Oracle coherence
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remedia
No detection rules found.
No public exploits indexed.
arXiv
ODDFUZZ: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing
arxiv_fulltext·2023-04-09
ODDFUZZ: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing
: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing
Sicong Cao^ , Biao He^ , Xiaobing Sun^ , Yu Ouyang^ , Chao Zhang^ , Xiaoxue Wu^ , Ting Su^ ,
Lili Bo^ , Bin Li^ , Chuanlei Ma^ , Jiajia Li^ , Tao Wei^
^ Yangzhou University ^ Ant Group ^ Tsinghua University ^ East China Normal University
^ \DX120210088, xbsun, xiaoxuewu, lilibo, lb\@yzu.edu.cn,
^ \hb187361, yu.oyy, chuanlei.mchl, jiajia.lijj, lenx.wei\@antgroup.com,
^ [email protected], ^ [email protected]
## Abstract
Java deserialization vulnerability is a severe threat in practice. Researchers have proposed static analysis solutions to locate candidate vulnerabilities and fuzzing solutions to generate proof-of-concept (PoC) serialized objects to trigger them.
However, existing soluti
Tenable
Oracle July 2021 Critical Patch Update Addresses 231 CVEs
blogs_tenable·2021-07-21
Oracle July 2021 Critical Patch Update Addresses 231 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2021-01-20
Published
Exploited in the wild