Impact
A critical flaw in Oracle Coherence allows an unauthenticated attacker who can reach the system over TCP to take control of the Coherence service. The vulnerability is caused by missing authentication checks (CWE‑306) in the Core component, enabling the attacker to bypass required authentication and execute arbitrary code, resulting in a full takeover of confidentiality, integrity and availability of the service.
Affected Systems
The vulnerability affects Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS 3.1 score of 9.8 signals a severe attack possibility with no authentication required, while the EPSS score of less than 1% indicates that the likelihood of exploitation is currently low and the flaw is not listed in the CISA KEV catalog. Nonetheless, because the attacker only needs network access to the designated TCP ports, the potential for a remote compromise remains high if the environment is not properly secured.
OpenCVE Enrichment