Impact
Oracle Coherence is vulnerable to a weakness that allows an unauthenticated attacker with network access through HTTP to modify, insert or delete data, as well as read restricted data. The flaw is in the Coherence Core component and results in both confidentiality and integrity impacts, but does not affect availability. The CVSS 3.1 base score is 5.4, reflecting moderate severity with low confidentiality and integrity impacts.
Affected Systems
The affected systems are Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all part of Oracle Fusion Middleware. These versions are listed by Oracle as impacted and may expose the mentioned data through the Coherence HTTP interface.
Risk and Exploitability
The risk of exploitation is low in terms of likelihood, as indicated by an EPSS score of less than 1%. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely remote over the network, requiring no authentication and accessed via HTTP. If successful, the attacker can obtain or alter data accessible to Coherence, potentially affecting downstream applications that rely on this data. Given the moderate CVSS score and low EPSS, the immediate risk is moderate, though an exposed endpoint could be leveraged to compromise other product components, as denoted by the scope change statement.
OpenCVE Enrichment