Impact
A vulnerability exists in the core component of Oracle Coherence that allows an attacker who already has a low‑privileged account on the host to compromise the application. Successful exploitation can lead to a full takeover, resulting in loss of confidentiality, integrity and availability of data managed by Coherence.
Affected Systems
The affected products are Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These versions are used in Oracle Fusion Middleware deployments and are vulnerable when running on any infrastructure where they are installed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local vulnerability that requires only low attacker privileges and no user interaction. The EPSS score of less than 1% suggests exploitation is not widespread yet, but the vulnerability is easily exploitable in environments where an attacker can log on to the host. The KEV status shows it is not yet listed in CISA’s catalog, but the risk remains significant because a single compromised system can lead to full application control.
OpenCVE Enrichment