Impact
A missing authentication check in the HTTP interface of Oracle Coherence allows an unauthenticated attacker to send requests that can lead to full takeover of the Coherence deployment. This flaw corresponds to CWE-306: Missing Authentication for Critical Functionality. The vulnerability is executable over the network and requires no prior credentials. Compromise grants the attacker control over confidentiality, integrity, and availability of the system.
Affected Systems
Oracle Coherence for Oracle Fusion Middleware. Versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable.
Risk and Exploitability
The CVSS base score of 9.8 signals a critical vulnerability with network access (AV:N) and no authentication required (PR:N). The EPSS score shows a very low likelihood of exploitation. Despite this, the vulnerability's lack of authentication controls makes any exposed HTTP endpoint a high-priority risk. It is not listed in the CISA KEV catalog, but the potential for complete system compromise warrants rapid remediation.
OpenCVE Enrichment