Impact
This weakness, classified as CWE-284 (Improper Access Control), allows an attacker with low privileges and network access over TCP to take full control of Oracle Coherence instances. The flaw is easily exploitable and can lead to complete compromise, affecting confidentiality, integrity, and availability. The CVSS base score of 8.8 reflects these severe impacts, and the attack vector is through direct network contact with the Coherence service.
Affected Systems
Vulnerable products include Oracle Coherence shipped with Oracle Fusion Middleware. Affected releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All four versions are listed as susceptible by the vendor’s advisory.
Risk and Exploitability
The risk is high, with a CVSS score of 8.8 and an EPSS score of less than 1 %, indicating a low current exploitation probability but a significant potential impact. The vulnerability is not yet in the CISA KEV catalog. An attacker can exploit the flaw by connecting over the exposed TCP interface, requiring only low privileges. Because the exploit is network‑based and does not require user interaction, it poses a serious threat to any Coherence deployment exposed to hostile networks.
OpenCVE Enrichment