Impact
Oracle Coherence is vulnerable to a remote code execution flaw that allows an unauthenticated attacker with network access via TCP to compromise the product. The vulnerability results in full takeover of Oracle Coherence, affecting confidentiality, integrity, and availability as stated by the CVSS 3.1 vector. The vulnerability exploits a missing authentication mechanism, leading to severe impact on systems that expose the relevant Coherence ports over a network.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Coherence product for Fusion Middleware. The versions impacted are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 as listed in Oracle’s security alert. Older or newer releases are not reported to be affected according to the current CNA information.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, while the EPSS score of less than 1% shows a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can execute the flaw by connecting to the Coherence service over TCP without authentication, making it easily exploitable in open or poorly segmented networks.
OpenCVE Enrichment