Impact
The vulnerability allows an unauthenticated attacker to execute arbitrary code on Oracle Coherence by abusing insecure handling of TCP connections. Once exploited, the attacker can gain full control of the Coherence cluster, potentially compromising any downstream applications and data that rely on it. This flaw results in complete loss of confidentiality, integrity, and availability, and is categorized as a credential-less remote code execution weakness (CWE-306).
Affected Systems
Oracle Coherence, a component of Oracle Fusion Middleware, is impacted. The vulnerable versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 reflects the severity of remote code execution with complete system compromise. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Still, the attack vector requires only network access to exposed Coherence TCP ports, meaning an attacker only needs to reach these ports to leverage the flaw. Given the high impact and remote execution capabilities, the risk to any exposed system remains significant.
OpenCVE Enrichment