Impact
Oracle Coherence, part of Oracle Fusion Middleware, has a flaw that permits an unauthenticated attacker to gain full control of the service through HTTP traffic. The vulnerability enables an attacker to compromise confidentiality, integrity, and availability, effectively taking over the Coherence cluster. The flaw is classified under CWE‑306 (Missing Authentication).
Affected Systems
The affected releases are Oracle Coherence 12.2.1.4.0 and 14.1.1.0.0. Based on the description, it is inferred that any deployment using these versions without the latest security update is vulnerable and may allow a remote attacker to compromise the system.
Risk and Exploitability
Based on the description, the likely attack vector is an unauthenticated HTTP request to an exposed Oracle Coherence endpoint. A remote attacker does not need credentials. Though the EPSS score is less than 1%, indicating a very low current exploitation probability, the CVSS base score of 9.8 shows severe impact across confidentiality, integrity, and availability. Because the vulnerability is not listed in the CISA KEV catalog, no publicly known exploits exist yet, but the combination of zero‑authentication and full takeover potential warrants urgent remediation.
OpenCVE Enrichment