← Vulnerability feed

Vulnerability record · CVE-2020-14756 · published 20 January 2021

CVE-2020-14756: Oracle Coherence Core Components unauthenticated remote takeover

Oracle · Coherence

Oracle Coherence Core Components contains an easily exploitable flaw reachable over IIOP and T3 that lets an unauthenticated network attacker compromise the product. Oracle rates it CVSS 3.1 9.8, and the affected supported versions are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. The record does not describe the underlying weakness beyond NVD-CWE-noinfo, so the exact root cause is not stated.

9.8 CVSS 3.1 Critical EPSS 75% · top 0.5%
9.8CVSS 3.1 base score, v2 7.5
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS percentile makes this a top remediation priority despite no KEV listing.

What it is

Oracle Coherence Core Components contains an easily exploitable flaw reachable over IIOP and T3 that lets an unauthenticated network attacker compromise the product. Oracle rates it CVSS 3.1 9.8, and the affected supported versions are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. The record does not describe the underlying weakness beyond NVD-CWE-noinfo, so the exact root cause is not stated.

Impact

Successful exploitation results in takeover of Oracle Coherence, with high confidentiality, integrity and availability impact. The attacker gains control of the affected component rather than a limited read or denial of service.

Attack surface

Reached over the network via IIOP and T3; the CVSS vector shows no privileges required and no user interaction. Any host exposing those Coherence interfaces to untrusted networks is in scope.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.74753 (99.478th percentile), indicating high predicted exploitation activity. References are patch and vendor advisory only, with no public exploit tag supplied.

What to do

  • Apply the Oracle January 2021 Critical Patch Update for Coherence, and the January 2022 update where it applies to your version.
  • Restrict network access to IIOP and T3 ports so only trusted hosts and management networks can reach Coherence.
  • Disable or block IIOP and T3 where they are not required by the deployment.
  • Inventory Coherence instances and confirm which of the listed versions are still running, then upgrade or isolate those that cannot be patched.
  • Monitor vendor advisories for updated guidance since the record does not detail the root cause.

Detection

  • Alert on unexpected inbound connections to Coherence IIOP and T3 ports from untrusted sources.
  • Baseline normal Coherence peer traffic and flag new or anomalous remote endpoints.
  • Watch for post-exploitation behavior on Coherence hosts such as new processes, outbound connections or configuration changes.
  • Correlate Coherence service logs with network flow data for signs of unauthenticated remote interaction.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14756 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed10.0CVE-2026-60217Oracle coherence missing authentication for critical function vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.…EPSS 0.51%10.0CVE-2026-35307Oracle coherence improper access control vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.…EPSS 0.51%10.0CVE-2026-35308Oracle coherence improper access control vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affe…EPSS 0.51%9.8CVE-2026-60306Oracle coherence missing authentication for critical function vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.…EPSS 0.51%9.8CVE-2026-60308Oracle coherence missing authentication for critical function vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.…EPSS 0.51%9.8CVE-2026-60296Oracle coherence missing authentication for critical function vulnerabilityVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2020-14756), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.