Impact
The Oracle Coherence Core component contains a vulnerability of type improper access control (CWE-284) that, while allowing an unauthenticated attacker with network access via T3 and IIOP, is difficult to exploit. Successful exploitation would result in full takeover, impacting confidentiality, integrity, and availability. The vulnerability is represented by a CVSS 3.1 Base Score of 8.1 with a vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. The issue is limited to the Core component of the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% shows that exploitation is unlikely at present. Potential attackers would need to reach the T3 or IIOP ports, which are normally exposed to the network, and initial access is difficult. Once accessed, the attacker can control the Coherence instance, compromising all data and services it manages.
OpenCVE Enrichment