Impact
This vulnerability enables an unauthenticated attacker who can reach the Oracle Coherence service over TLS to create, delete, or modify data, or simply read all protected data. The CVSS v3.1 base score of 9.1 reflects high confidentiality and integrity impacts with no availability change. The attack requires no authentication but demands network access to the Coherence endpoints, meaning that any exposed listener can be targeted.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These are components of Oracle Fusion Middleware used for distributed caching and data storage.
Risk and Exploitability
The EPSS score of less than 1% indicates a low likelihood of widespread exploitation, and the vulnerability is not yet listed in CISA KEV. However, the high CVSS score and the fact that the attack vector is network‑based via TLS mean that an attacker with internet or internal network access to the Coherence cluster can initiate the exploitation. The lack of authentication on the exposed interface represents a classic improper access control flaw, making the risk significant for any organization deploying an exposed Coherence service.
OpenCVE Enrichment