Impact
Oracle Coherence, part of Oracle Fusion Middleware, has a critical flaw that lets an attacker without authentication and with simple TCP network access compromise the system. The vulnerability, rated CVSS 9.8, grants full confidentiality, integrity, and availability impact, effectively allowing a remote takeover of the application.
Affected Systems
Affected Oracle Coherence releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are shipped by Oracle Corporation and can be found under the Oracle Coherence product line.
Risk and Exploitability
The risk is high due to a CVSS score of 9.8 and an EPSS score of less than 1 %, indicating a low probability of widespread exploitation at this time but a severe impact if exploited. The vulnerability is not yet listed in the CISA KEV catalog. Likely exploitation requires only TCP connectivity to exposed Coherence ports, no authentication or user interaction, and can be achieved remotely.
OpenCVE Enrichment