Impact
Oracle Coherence, a component of Oracle Fusion Middleware, has a flaw in its Core module that lets an unauthenticated attacker send HTTP traffic to the service and seize control of it. The weakness is an Access Control issue (CWE–284) and can give the attacker confidentiality, integrity, and availability compromise. The CVSS 3.1 score of 9.8 reflects this high level of impact.
Affected Systems
Affected parties include Oracle Corporation’s Oracle Coherence product. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable when the HTTP interface is reachable from external networks.
Risk and Exploitability
The severity score of 9.8 signals a critical risk, but the EPSS score of less than 1% indicates that zero‑day exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation to date. The attack vector is an unauthenticated HTTP request, implying that any system exposing Coherence over the network could be targeted without prior credentialing.
OpenCVE Enrichment