Impact
A low‑privileged attacker with network access to an Oracle Coherence deployment can read and modify data without authorization, enabling updates, insertions, deletions, and unauthorized read access to a subset of data. The weakness stems from insufficient access control on HTTP endpoints, compromising the confidentiality and integrity of the data stored in the Coherence cluster.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are bundled within Oracle Fusion Middleware and may be deployed on‑premises or in cloud environments that expose Coherence HTTP interfaces to the public or internal networks.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate severity, with confidentiality and integrity impacts but no availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation, yet the vulnerability remains actionable since the attack vector is network based over HTTP, requires only low privilege and no user interaction, and can be leveraged by an adversary with network access to the Coherence instance.
OpenCVE Enrichment