Impact
Vulnerability in Oracle Coherence allows an attacker who can reach the service over HTTP to take full control of the application. The flaw is an unauthenticated access issue that permits remote execution, causing total compromise of confidentiality, integrity and availability. The weakness corresponds to improper access control, enabling the attacker to alter or read all protected data and processes.
Affected Systems
Oracle Corporation's Oracle Coherence product, versions 12.2.1.4.0 and 14.1.1.0.0, is affected. The vulnerability exists in the Core component and can be reached by any host that can make HTTP requests to the Coherence service.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests a low probability of exploitation at this time. The CVE is not listed in CISA’s KEV catalog. Attacks would likely occur over an exposed HTTP interface without authentication, so network access is the primary requirement. The impact would be a full takeover of the Coherence server.
OpenCVE Enrichment