Impact
Oracle Coherence is a distributed caching and data sharing component of Oracle Fusion Middleware. A flaw in its Core component allows an unauthenticated attacker to influence the application through HTTP requests. Successful exploitation can cause the system to hang or crash repeatedly, resulting in a denial of service, and can also permit unauthorized insertion, update, or deletion of cached data. The flaw involves resource exhaustion (CWE‑400), producing tangible integrity and availability impacts without affecting confidentiality.
Affected Systems
Affected versions are Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All are supported release streams commonly deployed across production environments that rely on Coherence for high‑availability caching and distributed data structures.
Risk and Exploitability
The CVSS base score of 6.5 signifies a moderate risk level, while the EPSS score of less than 1% indicates current exploitation activity is not widely observed. The vulnerability is not listed in the CISA KEV catalog, but it remains a serious risk where Coherence is exposed to external networks. Based on the description, the likely attack vector is network access through the exposed HTTP interface, which requires no authentication. Exploitation involves sending crafted HTTP requests that trigger exceptions or memory exhaustion, leading to repeated service crashes and unauthorized data changes. The combination of availability loss and integrity compromise makes this a high‑impact threat for organizations that depend on Coherence for critical services.
OpenCVE Enrichment