Impact
A flaw in Oracle Coherence allows an unauthenticated attacker who can reach the service over HTTP to take complete control of the Coherence instance. The vulnerability can be exploited with little effort, leading to full compromise of confidentiality, integrity, and availability. The CVSS vector indicates that confidentiality, integrity, and availability are all high impact, and the base score is 9.8.
Affected Systems
Vendor Oracle Corporation's Coherence product is affected in versions 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Risk and Exploitability
With a CVSS score of 9.8, the weakness is critical. The EPSS score is under 1%, suggesting that current exploitation activity is low, but the potential damage is catastrophic. The vulnerability is not listed in the CISA KEV catalog, yet the attack requires only network access to the vulnerable HTTP endpoint and no authentication, making it likely to be leveraged once discovered.
OpenCVE Enrichment