Impact
A flaw in Oracle Coherence’s Core component, identified as CWE‑306, allows an attacker who already has a low‑privilege account and can reach the service over TCP to take full control of the Coherence service. The vulnerability can lead to loss of confidentiality, integrity, and availability and is rated CVSS 8.8 for its high impact.
Affected Systems
Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected; any installation of these versions exposed to a network is vulnerable.
Risk and Exploitability
The EPSS score is less than 1 %, and the flaw is not listed in CISA’s KEV catalog, indicating a low probability of mass exploitation. However, the network‑based attack vector requires only low privileges and therefore all exposed Coherence instances are at risk if the listed versions are in use.
OpenCVE Enrichment