Impact
The flaw arises from a missing authentication check in the core component of Oracle Coherence, categorized as CWE‑306. An attacker who can reach the service over the exposed TCP port can send unauthenticated requests that trigger a compromise of the Coherence instance. The impact is full control over the service, which can lead to loss of confidentiality, integrity, and availability of the data stored or provided by Coherence, and can also affect other products that use Coherence, producing a scope change.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions run as part of Oracle Fusion Middleware and are commonly deployed in enterprise environments for distributed caching and in‑memory data grids.
Risk and Exploitability
The CVSS v3.1 base score of 10.0 signals the highest severity, while the EPSS score of less than 1% indicates that widespread exploitation is currently low. Because the vulnerability is not listed in the CISA KEV catalog, the known exploitation risk is limited, but the lack of authentication requirement and the need for only network connectivity over a public port makes the attack readily achievable from any host that can reach the Coherence service. Successful exploitation would enable complete takeover of the target server.
OpenCVE Enrichment