Impact
A flaw in Oracle Coherence’s Core component permits an attacker without credentials to connect over HTTP and retrieve or alter data. The vulnerability compromises confidentiality and allows the modification or deletion of information that should be protected. No code execution or denial‑of‑service is described, so the primary risk is unauthorized access to critical business data.
Affected Systems
Oracle Coherence products from Oracle Corporation, specifically versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, are impacted. All users of these releases should verify their environment against the listed versions.
Risk and Exploitability
The CVSS score of 8.2 highlights the severity of the confidentiality and integrity impacts. The EPSS score of less than 1% indicates a low current exploit probability, yet the vulnerability remains present in widely deployed systems. The attack vector is inferred to be remote over HTTP; an unauthenticated attacker can exploit it if the Coherence service is reachable from the network. The vulnerability is not listed in CISA’s KEV catalog, but the potential for data exposure warrants immediate attention.
OpenCVE Enrichment