Impact
The vulnerability in the Oracle Coherence Core component permits an unauthenticated attacker with network access over TCP to compromise the system. If successfully exploited, the attacker can take over the Oracle Coherence cluster, leading to loss of confidentiality, integrity, and availability. This behavior is reflected in a CVSS v3.1 Base Score of 9.8, indicating a high severity where the flaw can result in full system takeover.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and are typically used in distributed caching and data grid deployments.
Risk and Exploitability
The CVSS score of 9.8 shows a severe impact, and the EPSS score of less than 1% suggests the likelihood of exploitation at present is low but non‑zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the exposed TCP interface from any networked host; no authentication or explicit authorization is required. This makes the attack vector straightforward, and if an exploit is deployed, it can lead to a full compromise of the affected Oracle Coherence instance.
OpenCVE Enrichment