Impact
Vulnerability in the Core component of Oracle Coherence allows an unauthenticated attacker with TCP network access to cause a denial of service by forcing the application to hang or crash. Moreover, the flaw permits unauthorized update, insert, or delete operations on data that the Coherence instance manages, leading to integrity compromise. The weakness arises from improper authentication controls (CWE‑306) and poses risks to both data integrity and system availability.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are impacted. These versions run as part of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS base score of 8.2 reflects a high severity impact on integrity and availability while the EPSS score of < 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs unauthenticated TCP access to the Coherence port to trigger the flaw, meaning any exposed host can be targeted.
OpenCVE Enrichment