Impact
Oracle Coherence, a component of Oracle Fusion Middleware, contains a flaw that permits an attacker with network access over TCP to authenticate without credentials and then execute arbitrary code. The vulnerability is characterized by missing authentication requirements, corresponding to CWE-306, and allows full control over the service. Successful exploitation results in the attacker gaining complete authority over the Coherence instance, which can compromise confidential data, modify or delete system state, and disrupt service availability.
Affected Systems
The affected product is Oracle Coherence from Oracle Corporation. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are listed as vulnerable. These releases are part of Oracle Fusion Middleware and are deployed in enterprise applications that expose Coherence services over a network.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 marks the flaw as critical, with maximum impacts on confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low overall probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because authentication is not required and the attack vector is a publicly reachable TCP port, any remote actor with network connectivity to the exposed Coherence service could potentially exploit the weakness, raising the risk for exposed deployments.
OpenCVE Enrichment