Impact
Oracle Coherence is vulnerable to an unauthenticated network attack that allows an attacker with TCP access to compromise the system; a successful exploit can lead to complete takeover of the affected Oracle Coherence instance, impacting confidentiality, integrity, and availability of the application and any data it manages. The issue is essentially an improper or missing authorization (CWE‑284) that allows unrestricted access through TCP, and the vulnerability is rated with a CVSS 3.1 Base Score of 9.8, indicating extremely high severity.
Affected Systems
Oracle Corporation’s Oracle Coherence product, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation is currently unlikely, yet the high CVSS score and the ability to fully compromise the system make it a critical risk. The inferred attack vector is a direct TCP‑based unauthenticated connection to the Coherence service, requiring no special privileges or authentication to gain full control.
OpenCVE Enrichment