Impact
Oracle Coherence contains a flaw that allows a low‑privileged attacker who can reach the physical communication segment attached to the hardware to compromise the component. The vulnerability permits full confidentiality, integrity, and availability impact on the affected Coherence installation and can trigger a scope change that may affect additional products in the environment.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. Products other than Coherence such as components of Oracle Fusion Middleware may also be impacted due to the scope change, although specific affected products beyond Coherence are not listed.
Risk and Exploitability
The flaw scores a CVSS 3.1 base of 9.0 with AV:A, AC:L, PR:L, UI:N, S:C, meaning a local or adjacent network attacker with low privileges can fully compromise Coherence. EPSS is < 1%, indicating exploitation likelihood is currently very low but not zero. The vulnerability is not listed in the CISA KEV catalog. An attacker would need physical network access to the hardware where Coherence runs and could then use the local‑network attack surface to elevate privileges and gain full control of the Coherence cluster, potentially impacting other products in the environment.
OpenCVE Enrichment