Vulnerability record · CVE-2020-14756 · published 20 January 2021
CVE-2020-14756: Oracle Coherence Core Components unauthenticated remote takeover
Oracle · Coherence
Oracle Coherence Core Components contains an easily exploitable flaw reachable over IIOP and T3 that lets an unauthenticated network attacker compromise the product. Oracle rates it CVSS 3.1 9.8, and the affected supported versions are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. The record does not describe the underlying weakness beyond NVD-CWE-noinfo, so the exact root cause is not stated.
Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile makes this a top remediation priority despite no KEV listing.
What it is
Oracle Coherence Core Components contains an easily exploitable flaw reachable over IIOP and T3 that lets an unauthenticated network attacker compromise the product. Oracle rates it CVSS 3.1 9.8, and the affected supported versions are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. The record does not describe the underlying weakness beyond NVD-CWE-noinfo, so the exact root cause is not stated.
Impact
Successful exploitation results in takeover of Oracle Coherence, with high confidentiality, integrity and availability impact. The attacker gains control of the affected component rather than a limited read or denial of service.
Attack surface
Reached over the network via IIOP and T3; the CVSS vector shows no privileges required and no user interaction. Any host exposing those Coherence interfaces to untrusted networks is in scope.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.74753 (99.478th percentile), indicating high predicted exploitation activity. References are patch and vendor advisory only, with no public exploit tag supplied.
What to do
- Apply the Oracle January 2021 Critical Patch Update for Coherence, and the January 2022 update where it applies to your version.
- Restrict network access to IIOP and T3 ports so only trusted hosts and management networks can reach Coherence.
- Disable or block IIOP and T3 where they are not required by the deployment.
- Inventory Coherence instances and confirm which of the listed versions are still running, then upgrade or isolate those that cannot be patched.
- Monitor vendor advisories for updated guidance since the record does not detail the root cause.
Detection
- Alert on unexpected inbound connections to Coherence IIOP and T3 ports from untrusted sources.
- Baseline normal Coherence peer traffic and flag new or anomalous remote endpoints.
- Watch for post-exploitation behavior on Coherence hosts such as new processes, outbound connections or configuration changes.
- Correlate Coherence service logs with network flow data for signs of unauthenticated remote interaction.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2021.html | PatchVendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | PatchVendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2021.html | PatchVendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | PatchVendor Advisory |
Track CVE-2020-14756 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-14756), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.