Impact
A vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to compromise the system. The weakness is a missing authentication flaw (CWE-306), enabling unauthorized access. Successful exploitation can lead to full takeover of the Coherence instance, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
The affected products are Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, which are part of Oracle Fusion Middleware.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.8 reflects critical severity. Nevertheless, because the attack vector is remote over TCP and does not require authentication, the risk remains high. Organizations with exposed Coherence instances should treat this as a critical threat.
OpenCVE Enrichment