Impact
The flaw in Oracle Coherence 15.1.1.0.0 is an easily exploitable network vulnerability that permits a low‑privileged attacker with TCP access to compromise the core component and force a temporary loss of service availability. The weakness, described by CWE-400, is improper handling of inbound traffic that can trigger resource exhaustion, leading to a partial denial of service with no compromise to confidentiality or integrity. The impact is limited to service disruption rather than data exfiltration or code execution.
Affected Systems
Oracle Coherence, part of Oracle Fusion Middleware, is affected when running version 15.1.1.0.0. This is the only version explicitly listed as vulnerable in the Oracle information.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 indicates a moderate severity with availability impact only. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild, and the vulnerability is not included in CISA’s KEV catalog. Attackers need network access to the Coherence cluster and can achieve the denial of service from a low‑privileged account, but no privileged escalation or data compromise is required. Overall risk is moderate but the probability of successful exploitation remains low.
OpenCVE Enrichment