Impact
Oracle Coherence contains a flaw in its core component that allows a high‑privileged attacker who has local access to the host where Coherence runs to read or obtain all data stored or accessible through the Coherence cluster. The vulnerability is classified as a CWE‑284 Improper Access Control weakness; it does not provide denial of service or code execution but delivers full confidentiality compromise. Because the attack requires local privileged access, it is not a network‑based vulnerability, and the attacker can gain read‑only visibility into all Coherence data once the flaw is exploited, potentially exposing sensitive business information.
Affected Systems
Affected systems are Oracle Coherence version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The product is supplied by Oracle Corporation and is part of the Oracle Fusion Middleware stack.
Risk and Exploitability
With a CVSS 3.1 base score of 6.0 the vulnerability is rated moderate. The EPSS score is below 1 %, indicating a very low current exploitation probability, and it is not listed in CISA’s KEV database. The likely attack vector is local and requires high‑privileged infrastructure access; no network exposure is needed. When the flaw is exploited, an attacker obtains full read‑only visibility into all Coherence data, potentially leaking sensitive information. The CVSS vector indicates a scope change, meaning that the impact could cascade to other Oracle products that rely on the compromised Coherence instance.
OpenCVE Enrichment