Impact
An unauthenticated attacker who can reach the affected Oracle Coherence application over TCP may exploit a flaw in the Core component to fully compromise the Coherence service. The vulnerability allows the attacker to take control of the application, resulting in complete loss of confidentiality, integrity, and availability for the data and services managed by Coherence. It is a high‑impact remote code execution flaw.
Affected Systems
Affected products are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. All these versions are supported by Oracle and should be updated to the latest patch series.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests that the probability of exploitation is currently very low, yet the impact of an exploit is catastrophic. The vulnerability is not listed in the CISA KEV catalog. Attackers would need only network connectivity to a listening TCP port and can exploit the flaw without authentication or user interaction.
OpenCVE Enrichment