Impact
Oracle Coherence, part of Oracle Fusion Middleware, contains a flaw that permits an unauthenticated attacker with network connectivity to a Coherence HTTP endpoint to seize control of the application. The vulnerability can be exploited to bypass authentication and perform arbitrary actions, causing compromise of confidentiality, integrity, and availability. The flaw matches CWE-306: Missing Authentication for Critical Function, and is classified as a high‑severity remote exploitation with the potential for persistent, system‑wide impact once the attacker gains entry.
Affected Systems
Oracle Corporation’s Oracle Coherence product is affected. Supported releases with this flaw include version 12.2.1.4.0 and 14.1.1.0.0. These versions run on a variety of platforms where Coherence provides distributed data caching and messaging capabilities.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 reflects extreme impact and an ease of attack: Network attacker, low access complexity, no privilege or user interaction. EPSS indicates a probability of less than 1 % at the time of the analysis but the flaw’s remote nature and lack of authentication mean any reachable HTTP interface could be abused. The vulnerability is not listed in CISA’s KEV catalog, but that does not reduce its risk. An attacker would target exposed HTTP ports on Coherence nodes, send a crafted request and gain administrative or execution capabilities without requiring credentials.
OpenCVE Enrichment