Impact
A vulnerability in Oracle Coherence permits an unauthenticated attacker with network access over TCP to take full control of the system. This represents an improper access control flaw (CWE‑306) that compromises confidentiality, integrity, and availability. The condition is easily exploitable, with a CVSS v3.1 base score of 9.8.
Affected Systems
The affected product is Oracle Coherence for the Oracle Fusion Middleware stack. Vulnerable releases include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Risk and Exploitability
The severity is high (CVSS 9.8) but the EPSS score is below 1%, indicating low to moderate exploitation likelihood in the current data set. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote TCP no authentication or user interaction. An attacker can send crafted packets to trigger the flaw and achieve arbitrary code execution on the host running Coherence.
OpenCVE Enrichment