Impact
The Oracle Coherence product contains a flaw in its HTTPS handling that allows an unauthenticated attacker to gain full control of the system. An attacker who can reach the Coherence server over HTTPS can execute arbitrary code, read or modify data, and take over the application. This vulnerability is rated CVSS 3.1 9.8 and affects confidentiality, integrity, and availability.
Affected Systems
Affected versions are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0, which are part of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS base score of 9.8 signifies a high severity, while the EPSS score of < 1% indicates a low but not zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. Attackers can exploit the flaw over an unauthenticated HTTPS connection, making the vulnerability easily reachable for remote attackers who can reach the network segment that hosts the Coherence instance.
OpenCVE Enrichment