Impact
A low‑privileged attacker with network access over TCP can exploit a flaw in the Core component of Oracle Coherence, allowing unauthorized updates, inserts, deletes and reads of a subset of stored data. The vulnerability is a moderate severity issue (CVSS 5.4) that impacts confidentiality and integrity but has no availability impact.
Affected Systems
Oracle Coherence, part of Oracle Fusion Middleware, is affected in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. The CVE notes that the flaw resides in the Core component running in these versions.
Risk and Exploitability
The CVSS Base Score of 5.4 indicates moderate severity; the EPSS score of less than 1% signifies a low probability of exploitation in the current threat landscape, and the issue is not listed in CISA’s KEV catalog. Attackers need only basic network connectivity to a Coherence instance and low privilege to exploit the flaw, making the attack vector relatively simple. Applying the vendor patch when it becomes available, restricting TCP access to trusted hosts, and monitoring for unauthorized data modification attempts are the recommended defenses.
OpenCVE Enrichment