Impact
CWE-284, an Improper Access Control flaw, allows an attacker to execute arbitrary code without authentication over the network. This vulnerability can compromise the confidentiality, integrity, and availability of the affected system, effectively giving an attacker full control of the Coherence deployment.
Affected Systems
Oracle Corporation’s Coherence product is vulnerable in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These releases are part of Oracle Fusion Middleware and are reachable through their HTTP interface.
Risk and Exploitability
The CVSS base score of 9.8 highlights a high severity vulnerability that can be exploited with low effort and no authentication. Though the EPSS score is below 1%, indicating a low yet non‑zero probability of exploitation, its inclusion in the CISA KEV catalog is not yet noted. The likely attack vector is via the HTTP port exposed by Coherence; an unauthenticated attacker with network access can trigger the vulnerability and fully takeover the application.
OpenCVE Enrichment