Impact
Oracle Coherence contains an easily exploitable authorisation flaw that allows an attacker with local access on the host where the service runs to fully compromise the instance. The vulnerability permits privilege escalation that leads to complete takeover, enabling the attacker to read, modify or delete data and disrupt service availability. The weakness is an authorisation failure (CWE-269), exposing the system to confidentiality, integrity and availability breaches.
Affected Systems
The flaw affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, which are deployed as part of Oracle Fusion Middleware. Users running these releases are at risk if the environment is not appropriately hardened.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 (AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates the attack requires local access, no additional privileges, and escalates authority to all system components. The EPSS value of less than 1% shows a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Anyone able to log on to the host can exploit this flaw and gain full control over the Coherence instance.
OpenCVE Enrichment