Impact
This vulnerability exists in the Core component of Oracle Coherence and allows an attacker with high privileges and network access via HTTP to bypass normal access controls. It can lead to unauthorized reading of confidential data and modifying or deleting entries, thereby compromising data integrity. The issue is evident from the CVSS vector which highlights high confidentiality impact and low integrity impact, confirming the potential for significant data exposure and alteration.
Affected Systems
Affected products are Oracle Corporation's Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All these versions are listed in the advisory as vulnerable and would need to be updated or otherwise secured to mitigate the risk.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, but the vulnerability is easily exploitable from any network location that can reach the HTTP endpoint, making it a realistic threat. The EPSS score of less than 1% suggests low current exploitation probability, however the vulnerability is not part of the CISA KEV catalog, meaning there is no evidence of widespread attacks yet but the potential remains. Exploit likely requires an attacker who has high privileges on the system or can elevate privileges through the compromised component.
OpenCVE Enrichment