Impact
A remote vulnerability in Oracle Coherence allows an unauthenticated attacker who can reach the appliance over TCP to gain full control of the system. The flaw provides an opportunity for compromise of confidentiality, integrity, and availability, and the associated weakness is improper authentication and authorization leading to remote code execution. The CVSS 3.1 base score of 9.8 indicates a critical severity.
Affected Systems
The affected product is Oracle Corporation’s Oracle Coherence, with supported versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The vulnerability is highly exploitable, requiring only network connectivity to the exposed TCP port and no credentials. An attacker could easily execute arbitrary code and takeover the Coherence instance. The EPSS score is under 1%, indicating a low overall probability of exploitation at this time, though the CVSS score remains high. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment