Impact
A flaw in Oracle Coherence 15.1.1.0.0 permits an attacker without authentication to send crafted TCP traffic that can cause the application to hang or crash repeatedly, leading to complete denial of service. In addition, the same vulnerability allows unauthorized updates, inserts, deletes, and reads of data exposed by the Coherence service, compromising both confidentiality and integrity of that data.
Affected Systems
Oracle Corporation’s Coherence product, version 15.1.1.0.0, is the only affected version listed. No other Oracle Fusion Middleware components or product versions are currently reported as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.6 indicates high severity with moderate confidentiality and integrity impact but high availability impact. EPSS indicates an extremely low likelihood of exploitation in the field (<1%). The vulnerability is not yet listed in CISA’s KEV catalog, suggesting no known active exploitation currently. Attack requires only network access to the Coherence TCP port and no authentication, making the threat vector easily exploitable by any remote endpoint capable of establishing a TCP connection to the target system.
OpenCVE Enrichment