Impact
This vulnerability allows an unauthenticated attacker with network access via TCP to take complete control of an Oracle Coherence instance, compromising confidentiality, integrity, and availability. The flaw resides in the core component and is identified as a weakness in authorization controls and lack of authentication. Successful exploitation results in full takeover of the Coherence service, permitting arbitrary code execution and data exfiltration.
Affected Systems
The flaw affects Oracle Coherence products distributed by Oracle Corporation in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are listed in the Oracle Coherence product line.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 marks this issue as critical. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the current window, and the vulnerability is not included in the CISA KEV catalog. Attackers only need TCP connectivity to the exposed Coherence service ports; no credentials are required. While network segmentation or firewall filtering can reduce exposure, the only definitive remedy is to apply the vendor‑issued fix.
OpenCVE Enrichment