Impact
The vulnerability resides in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. It allows an unauthenticated attacker with TCP network access to send crafted payloads that are processed by the Core module, resulting in uncontrolled code execution on the host. The result is a complete takeover of the Coherence cluster, with full compromise of confidentiality, integrity, and availability. The flaw is linked to an authentication bypass vulnerability (CWE-306).
Affected Systems
Oracle Coherence is deployed in distributed caching and data grid environments; the affected builds include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, the latest version available at the time of the advisory. Systems running these packages with the default unsecured TCP listeners exposed to an external network are highly susceptible.
Risk and Exploitability
With a CVSS v3.1 base score of 9.8, the vulnerability is classified as Critical, reflecting maximum impact on confidentiality, integrity, and availability. The EPSS score of less than 1% indicates that, according to current threat intelligence, there is a very low probability of exploitation observed in the wild today, and the issue is not yet listed in the CISA KEV catalog. However, the attack can be launched over plain TCP without authentication or privilege, making it broadly exploitable for any networked Coherence instance. The single-step exploitation flow suggests that once a malicious packet reaches a listening Coherence node, the Core component immediately processes it and yields remote code execution, enabling a complete compromise of the platform.
OpenCVE Enrichment