Impact
A vulnerability in Oracle Coherence allows an attacker to connect over TCP without authentication and take full control of the application. The flaw permits the attacker to read, modify, or delete any data and to execute arbitrary operations, resulting in complete compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle Coherence product, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates a critical severity, and the EPSS score of less than 1% shows a small but existing exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a remote TCP connection that requires no authentication and can be attempted by any external actor with network access.
OpenCVE Enrichment