Impact
The vulnerability in Oracle Coherence, part of Oracle Fusion Middleware, permits an unauthenticated attacker with network access to a vulnerable instance to compromise the service through an exposed TCP interface. The vulnerability is classified as difficult to exploit but, once successfully leveraged, allows full takeover of the Coherence service, potentially granting an attacker the ability to read, modify or delete data, execute arbitrary code, and disrupt service availability. This weakness aligns with improper access control or authentication issues, as indicated by the lack of required credentials for remote interaction.
Affected Systems
Affected vendors and products include Oracle Corporation’s Oracle Coherence. The specific versions impacted are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The vulnerability applies to the core component of these releases, which can be identified by the corresponding common platform enumeration strings.
Risk and Exploitability
The CVSS v3.1 score of 8.1 reflects severe confidentiality, integrity, and availability compromises. The EPSS score of less than 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is inferred to be network‑based over TCP, with no user interaction or elevated privileges required, meaning that remote exploitation is feasible from any network location that can reach the vulnerable port. Proper remediation requires applying the official patch or update as provided by Oracle and tightening network exposure of the service.
OpenCVE Enrichment