Impact
The vulnerability resides in the core component of Oracle Coherence and allows an unauthenticated attacker with network access via TCP to take control of the service. Successful exploitation results in full compromise of Oracle Coherence, giving the attacker the ability to read, modify, delete data and disrupt service availability. The weakness aligns with severe confidentiality, integrity and availability impacts as reflected by a CVSS 3.1 score of 9.8.
Affected Systems
Affected versions include Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical vulnerability, but the EPSS score of less than 1% suggests that current exploit rates are low. The vulnerability is not listed in CISA KEV, implying no confirmed exploitation in the wild yet. Nonetheless, the attack vector is an unauthenticated TCP connection to the Coherence service, meaning any host that can reach the port is potentially vulnerable. Exploitation requires no user interaction or credentials, making it an easy target for automated attackers.
OpenCVE Enrichment