cbcvebase.
CVE-2020-14756
published 2021-01-20

CVE-2020-14756: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0…

PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
74.75%
99.5th percentile
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

17 ranges
VendorProductVersion rangeFixed in
oraclecoherence
oraclecoherence
oraclecoherence
oraclecoherence
oraclecoherence
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework
oracleutilities_framework4.3.0.1.0 – 4.3.0.6.0
oracle_corporationutilities_framework
oracle_corporationutilities_framework
oracle_corporationutilities_framework
oracle_corporationutilities_framework
oracle_corporationutilities_framework
oracle_corporationutilities_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for unauthenticated inbound connections over IIOP and T3 protocols targeting Oracle Coherence, as these are the attack vectors for CVE-2020-14756
  • Detect Java deserialization gadget chain exploitation attempts delivered over T3/IIOP to Oracle Coherence Core Components
  • ·CVE-2020-14756 affects Oracle Coherence versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0; detections should be scoped to these versions
  • ·The vulnerability is exploitable remotely with no authentication and no user interaction required (CVSS 9.8), meaning any network-accessible Coherence instance is at risk without additional prerequisites
  • ·Attack surface includes both IIOP and T3 protocols; blocking or restricting both protocols at the network perimeter is necessary to reduce exposure

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
vendor_oracle9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.