Impact
The vulnerability is an unauthenticated flaw classified as CWE-306 that can be triggered over a TCP connection and results in the complete takeover of an Oracle Coherence instance. An attacker who can reach the vulnerable service does not need any prior authentication or UI interaction, and a successful exploitation gives the attacker full confidentiality, integrity, and availability control over the affected Coherence cluster.
Affected Systems
Oracle Coherence, part of Oracle Fusion Middleware, is affected for the following versions: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 9.8, indicating a critical severity with complete loss of confidentiality, integrity and availability. The EPSS score is below 1%, suggesting that exploit packages are not yet widely available, but the impact of a successful attack is catastrophic. The issue is not listed in the CISA KEV catalog, yet the combination of a high CVSS and a straightforward network‑level attack vector makes it a priority for mitigation.
OpenCVE Enrichment