Impact
Oracle Coherence, a component of Oracle Fusion Middleware, contains a vulnerability that allows an attacker with low privileges to send crafted TCP requests and cause the application to hang or crash, resulting in a complete denial of service. The flaw is classified as a low privileged attack that can be performed over the network, leveraging the public interfaces of the software. The impact focuses exclusively on availability, as stated by the CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with no compromise of confidentiality or integrity.
Affected Systems
Affected versions are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These releases are part of Oracle Fusion Middleware and are listed in the known CPE strings provided. Users running any of these versions should verify their current installation.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity focused on availability. The EPSS score is below 1%, indicating that the overall likelihood of exploitation in the wild is low, and the vulnerability is not currently listed in the CISA KEV catalog, reducing evidence of active exploitation. Nonetheless, because the exploitation requires only network access and low privilege, a determined attacker could repeatedly trigger crashes, which is why the higher impact of a compromised service should not be underestimated.
OpenCVE Enrichment