Impact
The vulnerability is an unauthenticated remote denial of service in Oracle Coherence that can be triggered over TCP. An attacker who can send crafted TCP packets to the exposed Coherence ports can cause the service to hang or crash, resulting in a complete denial of all Coherence functionality. This flaw results in a high‑impact availability attack with no impact on confidentiality or integrity.
Affected Systems
Oracle Coherence instances that are part of Oracle Fusion Middleware are affected, including versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Any installation that exposes the designated Coherence TCP ports over the network is vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 highlights a severe availability impact, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network access and no authentication, making the attack vector straightforward and readily achievable over TCP traffic.
OpenCVE Enrichment