Impact
Oracle Coherence, part of Oracle Fusion Middleware, contains a vulnerability that permits an unauthenticated attacker with TCP network access to compromise the system. The flaw allows the attacker to take full control over the Coherence service, leading to complete loss of confidentiality, integrity, and availability of the application. This missing‑authentication weakness is identified as CWE-306 and the vulnerability is a high‑severity weakness classified as Remote Code Execution, evidenced by the CVSS vector indicating no authentication required and full impact on all security properties.
Affected Systems
The affected product is Oracle Coherence across several major releases, specifically version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All these versions are listed by Oracle as vulnerable and are included in the advisory linked in the references. The vulnerable component is the Core module of the Coherence product.
Risk and Exploitability
The CVSS base score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates that, as of the latest data, the probability of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog, and the attack vector is a simple network‑based TCP connection that does not require user interaction or privileges. Because the attacker can gain unrestricted control, the risk is high for any environment that exposes Coherence to the network.
OpenCVE Enrichment