Impact
Oracle Coherence, a component of Oracle Fusion Middleware, contains a flaw in its core that allows an attacker who is not logged in to connect and gain unrestricted read access to all data stored in the Coherence cache. The vulnerability can be exercised through the standard TCP interface that Coherence exposes, and does not require any user interaction or privileges. Successful exploitation would allow the attacker to read or potentially modify critical application data, compromising confidentiality and potentially leading to larger application compromises.
Affected Systems
Oracle Corporation’s Coherence product versions 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected when deployed. If the Coherence service is reachable from an untrusted network or the internet, the vulnerability can be exercised.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high confidentiality impact with no impact to integrity or availability. The EPSS score of less than 1% suggests that exploitation attempts are uncommon at present, yet the lack of authentication and the fact that the flaw is remotely reachable via an open TCP channel make it a high‑risk threat. The vulnerability is not yet listed in the CISA KEV catalog, but it enables full data exposure and therefore should be corrected as soon as possible. Attack vectors are restricted to establishing a TCP connection to the Coherence service, after which the attacker can read data without further interaction. Natively, the flaw exploits missing or incorrect authentication checks and the absence of a proper authentication mechanism (CWE‑306).
OpenCVE Enrichment