Impact
A flaw in Oracle Coherence’s core component allows an unauthenticated attacker to gain full control over the application, compromising confidentiality, integrity, and availability. The weakness is consistent with improper access controls and authentication bypass, enabling remote compromise with minimal effort.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are impacted. Oracle Fusion Middleware customers running any of these releases are exposed to the risk.
Risk and Exploitability
The CVSS v3.1 score of 9.8 signals a critical severity, while the EPSS score of less than 1% suggests limited current exploitation but the potential for future attacks remains high. The vulnerability is not yet listed in CISA’s KEV catalog, yet the remote HTTP exposure enables a direct attack vector to achieve full system takeover.
OpenCVE Enrichment