Impact
The core component of Oracle Coherence is vulnerable to a low‑privilege HTTP request that allows an attacker to create, delete, or modify data stored in the service. The flaw enables unauthorized creation and deletion of objects and full read access to all data handled by Coherence, resulting in severe confidentiality and integrity compromise. The CVSS 3.1 base score of 9.6 reflects the high impact and the fact that the vulnerability is easily exploitable without additional prerequisites.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. The vulnerability is located in the Core component of the product and can affect systems running these releases.
Risk and Exploitability
The flaw can be triggered from any networked client that can reach the Coherence HTTP endpoint, even with a low‑privileged user account. The CVSS score of 9.6 indicates a critical rating. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the bug can change the scope of impact to additional products, organizations that rely on Coherence should treat this as a serious risk and act promptly. The primary attack vector is network based, via HTTP requests managed by the Coherence service.
OpenCVE Enrichment