Impact
The Oracle Coherence vulnerability is a missing authentication flaw in the core component, classified as CWE-306. An unauthenticated attacker who can reach the Coherence service over TCP can fully compromise the process, gaining control over the cluster. Successful exploitation removes confidentiality, integrity, and availability protections, allowing the attacker to read, modify, delete data or disrupt cluster operation.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These releases are part of Oracle's Fusion Middleware offering and are distributed by Oracle Corporation.
Risk and Exploitability
With a CVSS 3.1 base score of 9.8 the vulnerability is considered critical. The EPSS probability is below 1 % and the flaw is not listed in the CISA KEV catalog, indicating limited current exploitation but significant potential. Attackers need only network access to the exposed Coherence ports; no authentication or privilege escalation is required. As such, an attacker can immediately take control of the entire Coherence cluster once the vulnerability is triggered.
OpenCVE Enrichment