Impact
The vulnerability is a missing authentication flaw (CWE‑306) that exists in the core component of Oracle Coherence, part of Oracle Fusion Middleware. An unauthenticated attacker who can reach the service over a TCP connection can exploit the flaw to gain full control of the Coherence service. The attacker obtains the same privileges as the service process, enabling arbitrary code execution, sensitive data disclosure, and denial of service. CVSS 3.1 scores it as high severity, with complete confidentiality, integrity, and availability impact.
Affected Systems
Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. No other versions were listed as affected.
Risk and Exploitability
The vulnerability is rated CVSS 9.8 and has an EPSS score of less than 1 %. It is not currently listed in the CISA KEV catalog. The attack vector or special privileges, making exploitation straightforward for any attacker with network access to the target. The combination of high severity, low exploitation the affected product make this a high‑risk vulnerability.
OpenCVE Enrichment