Impact
The vulnerability allows an attacker who can reach Oracle Coherence over the network to bypass authentication entirely and obtain full control of the application. Once compromised, the attacker can modify, delete, or exfiltrate data, and launch further attacks against the surrounding environment. The CVSS 3.1 base score of 9.8 reflects the attacker's ability to execute code, alter data and cause denial of service, with high impacts on confidentiality, integrity, and availability.
Affected Systems
This flaw affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 across all supported releases.
Risk and Exploitability
The risk is high due to the lack of authentication required for exploitation and the potential for complete takeover. The EPSS score of less than 1% indicates current exploitation probability is low, but the severity remains high, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be remote over TCP based on the network access requirement mentioned in the description, allowing direct exploitation via Coherence’s listening endpoints.
OpenCVE Enrichment