Impact
A vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to trigger a hang or repeated crash of the Coherence service. The flaw is easily exploitable and can cause a complete denial of service, affecting only availability while no confidentiality or integrity impact has been reported. This flaw is a Resource Exhaustion vulnerability (CWE-400).
Affected Systems
Oracle Coherence from Oracle Corporation is impacted. The affected releases include version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. All these builds expose a remote TCP interface that can be abused without authentication.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity availability issue, and the EPSS score of less than 1% suggests the overall exploitation likelihood is currently low, though the vulnerability is still not listed in CISA KEV. The attack vector is likely a simple TCP connection to a known Coherence port, requiring no credentials. The probability of exploitation in the wild is low, and the impact of a successful attack is significant for environments that rely on Coherence for distributed caching or messaging.
OpenCVE Enrichment