Impact
This vulnerability allows an unauthenticated attacker with network access via TCP to fully compromise an Oracle Coherence instance, resulting in a complete system takeover. The impact covers confidentiality, integrity, and availability due to the CVSS vector indicating no requirement for user interaction and a high severity score of 9.8. This weakness is a CWE‑306 missing authentication for critical functions, permitting a remote attacker to gain privileges without authentication.
Affected Systems
The affected product is Oracle Coherence from Oracle Corporation. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable; updates later than these versions are not listed as affected.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical vulnerability, but the EPSS score of <1% shows that, as of this assessment, the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely over the network without authentication by connecting to the Coherence TCP interfaces, potentially executing arbitrary code and taking over the system.
OpenCVE Enrichment