Impact
The vulnerability resides in Oracle Coherence of Oracle Fusion Middleware. Supported versions 12.2.1.4.0 and 14.1.1.0.0 can be controlled by an attacker with network connectivity to the exposed HTTP interface. The flaw permits an unauthenticated attacker to execute arbitrary code and ultimately take over the Coherence cluster. The CVSS 3.1 base score of 9.8 reflects severe impacts on confidentiality, integrity, and availability, meaning a compromised cluster could expose, alter, or deny all data and services running atop it.
Affected Systems
Oracle Coherence 12.2.1.4.0 and 14.1.1.0.0, components of Oracle Fusion Middleware. These are distributed under the Oracle Coherence product line and identified by the vendor as the affected components.
Risk and Exploitability
The exploitation can be triggered from any host that can reach the HTTP service without authentication, making it a surface for remote attackers. The EPSS score of less than 1% suggests limited historical exploitation, yet the high CVSS score indicates that if discovered, consequences would be critical. The vulnerability is not listed in the CISA KEV catalog, but its combination of easy exploitation and catastrophic impact warrants immediate attention.
OpenCVE Enrichment