Impact
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 contain an authentication and access control flaw that allows an unauthenticated attacker with physical access to the local communication segment to compromise the application. The vulnerability can lead to unauthorized creation, deletion, or modification of critical data and grant full access to all data exposed by Coherence. The flaw is identified by weakness CWE‑284 and carries a CVSS 3.1 base score of 8.1, indicating significant confidentiality and integrity impact.
Affected Systems
The affected systems are Oracle Coherence version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, deployed within Oracle Fusion Middleware environments. Attackers who can reach the adjacent physical network segment to these appliances may exploit the flaw.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity, but the EPSS score of less than 1% indicates a very low probability for widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been actively leveraged. The likely attack vector is local or physical network access; exploitation requires proximity to the Coherence node’s communication segment. Successful exploitation would provide the attacker with complete unauthorized access to critical data, affecting confidentiality and integrity without impacting availability.
OpenCVE Enrichment