Impact
The flaw is a Missing Authentication issue (CWE-306) in the Core component of Oracle Coherence, allowing an unauthenticated attacker who can reach the system over HTTP to fully compromise the Coherence instance. A successful exploit results in a complete takeover, providing the attacker with full control of the system. The flaw leads to simultaneous confidentiality, integrity, and availability impacts, as reflected by the CVSS 3.1 base score of 9.8.
Affected Systems
Oracle Coherence from Oracle Corporation is affected. The versions listed in the CVSS information are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The vulnerability is tied exclusively to the Core component of these releases.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity; the EPSS score of less than 1 % suggests a very low probability of exploitation at the moment, and the vulnerability is not currently listed in the CISA KEV catalog. However, because the flaw is easily exploitable and requires only unauthenticated network access via HTTP, organizations should treat it as a high risk and prioritize remediation. If an attacker gains network access to the exposed HTTP endpoints, the attack can be conducted with minimal effort and without authentication.
OpenCVE Enrichment