Impact
Oracle Coherence’s Core component contains an Improper Authorization weakness that lets a low‑privileged attacker, who can reach the same physical network segment as the Coherence server, create, delete, or alter data stored in the cache. Successful exploitation can also grant the attacker read access to all data presented by Coherence services. The CVSS vector indicates high confidentiality and integrity impacts but no availability impact.
Affected Systems
Oracle Coherence from Oracle Corporation is affected in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. No other product variants are listed.
Risk and Exploitability
The CVSS base score of 8.7 signals high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at any given time. Because the attack vector is adjacent network (AV:A), any entity on the same physical communication segment can attempt the attack without user interaction. The scope change in the vector (S:C) signals potential impacts on other products that consume Coherence. Although not listed in the CISA KEV catalog, the vulnerability’s ability to compromise critical data and broaden access to multiple applications warrants prompt action.
OpenCVE Enrichment