Impact
The vulnerability resides in the Core component of Oracle Coherence and permits an unauthenticated network attacker to read a subset of data exposed by the application. The flaw does not grant code execution or modify data, but it enables confidential information disclosure. The CVSS vector indicates that confidentiality is impacted while integrity and availability remain unaffected.
Affected Systems
Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. These versions are part of Oracle Fusion Middleware and are typically deployed in distributed caching and data grid environments. The issue affects all installations that expose the Coherence service over the network without authentication controls.
Risk and Exploitability
The base score of 5.3 and an EPSS of less than 1% suggest moderate risk and low probability of exploitation, and the vulnerability is not currently catalogued in KEV. Attackers would need network connectivity to the TCP ports used by Coherence and no special privileges. Successful exploitation yields unauthorized read access to data, which could expose sensitive information to an attacker.
OpenCVE Enrichment