Impact
An unauthenticated attacker with access to the same physical communication segment as the Oracle Coherence Java Virtual Machine can exploit a flaw in the Core component. The vulnerability enables a local takeover, resulting in loss of confidentiality, integrity, and availability across the Coherence cluster.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, distributed by Oracle Corporation under the Oracle Fusion Middleware umbrella.
Risk and Exploitability
The CVSS base score is 8.8, the EPSS score is below 1 %, and the vulnerability is not listed in CISA KEV. The attack vector is local (AV:A) and requires no authentication or user interaction. Successful exploitation permits arbitrary code execution, data exfiltration, configuration tampering, and potential service disruption for all clients relying on the Coherence cluster.
OpenCVE Enrichment