Impact
Oracle Coherence, a core component of Oracle Fusion Middleware, contains a vulnerability that allows an unauthenticated attacker with network access over TCP to cause unauthorized creation, deletion, or modification of critical data accessible through the system. The flaw leads to a loss of confidentiality and integrity for all data handled by the affected Coherence deployment, while availability remains unaffected. The attack requires user interaction from a third party and, due to a scope change, can have cascading effects on other surrounding products.
Affected Systems
The vulnerability affects Oracle Corporation's Oracle Coherence product in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Administrators of Oracle Fusion Middleware environments that incorporate any of these Coherence versions need to verify their current build and consider remediation.
Risk and Exploitability
With a CVSS v3.1 base score of 9.3, the flaw is categorized as critical, reflecting substantial confidentiality and integrity impact. The EPSS score of less than 1 % indicates that widespread exploitation is currently expected to be rare, but the presence of the flaw and high score warrant timely action. The vulnerability is not flagged in the CISA KEV catalog at this time. The likely attack path involves an unauthenticated network connection over TCP to the Coherence service, followed by exploitation steps that require the victim to interact with the system, such as triggering a specific command or configuration change. Because the CVE notes a scope change, successful exploitation could also affect other components within the application stack.
OpenCVE Enrichment