Impact
The vulnerability is a Missing Authentication flaw that permits an unauthenticated attacker with TCP connectivity to an Oracle Coherence service to gain control of the service. This Missing Authentication flaw is inferred from the description, as the CVE states that no authentication is required. Successful exploitation can fully compromise the Coherence instance, leading to loss of confidentiality, integrity, and availability of all data and operations managed by Coherence. The weakness is identified as CWE‑306. No authentication is required, so any host that can reach the Coherence port can trigger the attack.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are distributed by Oracle Corporation as part of Oracle Fusion Middleware and are used in enterprise environments that rely on Coherence for distributed caching, data grid, and clustering.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.8 indicates a critical vulnerability affecting confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is not widely observed at present. The vulnerability is not yet listed in the CISA KEV catalog. An attacker only needs network access to the exposed Coherence TCP port, with no credentials, to exploit the flaw, making the attack vector highly accessible to remote attackers.
OpenCVE Enrichment