Impact
This vulnerability exists in the Core component of Oracle Coherence and permits an unauthenticated attacker to exploit the HTTP interface to fully compromise the system. The flaw essentially bypasses authentication, allowing the attacker to take control, thereby exposing confidentiality, integrity and availability of the application. The weakness is consistent with improper check for authorization (CWE-306).
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected; these are the only releases identified as vulnerable by Oracle.
Risk and Exploitability
The CVSS v3.1 score of 9.8 classifies it as critical, while the EPSS score of less than 1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack path involves sending specially crafted HTTP requests to an exposed Coherence service from an external network, with no authentication or user interaction required. Because the vulnerability is easily exploitable, an attacker who can reach the service can gain full administrative rights over the application.
OpenCVE Enrichment