Impact
The vulnerability, identified as an authentication bypass (CWE-306), allows an unauthenticated attacker to connect over TCP and compromise Oracle Coherence. Successful exploitation can result in total takeover of the Coherence service, leading to confidentiality, integrity, and availability impacts. The CVSS score of 9.8 underscores the severity of the flaw.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These editions are part of Oracle Fusion Middleware and can be found under Oracle’s product catalog for Core services.
Risk and Exploitability
With a CVSS Base Score of 9.8, the vulnerability is classified as critical. The EPSS score of < 1% suggests low current exploitation probability, and the issue is not listed in the CISA KEV catalog. The attack vector is network-based, requiring only TCP connectivity to the Coherence port, with no authentication needed, making it straightforward for remote attackers to exploit.
OpenCVE Enrichment