Impact
This vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to fully compromise the software. An attacker can send specially crafted data to a vulnerable node and gain control, resulting in a complete takeover of the Coherence cluster. The impact spans confidentiality, integrity and availability, disrupting data and services managed by Coherence.
Affected Systems
Affecting Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, this flaw impacts installations that expose the Coherence ports to the network. Network administrators must verify whether any of these versions are deployed within the organization and ensure that the software is isolated or patched.
Risk and Exploitability
The CVSS v3 high severity risk, with low attack complexity and no privileges required. The EPSS score is less than 1% and it is not listed in the CISA KEV catalog. Nevertheless, the flaw is exploited over the network through a TCP connection, requiring no authentication and affecting the entire system once an attacker can reach the vulnerable endpoint. Prompt remediation is therefore advised.
OpenCVE Enrichment