Impact
Vulnerability in Oracle Coherence Core allows an unauthenticated attacker with network access over HTTP to execute code and take over the system. The flaw, classified as CWE‑306, indicates that authentication is missing for the exposed interface. It provides full confidentiality, integrity, and availability control, enabling an attacker to compromise the entire Coherence deployment. It is categorized as a high‑impact remote code execution vulnerability.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. These releases are part of Oracle Fusion Middleware and may be deployed in distributed application clusters.
Risk and Exploitability
The CVSS v3.1 score is 9.8, indicating critical severity. Because the attack vector is network‑based and authentication is not required, the exploitability is high, but the EPSS score of less than 1% implies that the overall likelihood of active exploitation in the wild remains low at the time of reporting. The vulnerability is not listed in CISA's KEV catalog, but its ability to completely compromise a Coherence node makes it a top priority for patching.
OpenCVE Enrichment