Impact
This vulnerability allows an unauthenticated attacker with network access via TCP to gain complete control over Oracle Coherence. Successful exploitation can compromise confidentiality, integrity, and availability of the application, effectively resulting in a takeover of the Coherence service.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These are components of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical severity with high impacts across confidentiality, integrity and availability. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is likely a direct TCP connection to the Coherence service, where no authentication is required, enabling an attacker to remotely control the system.
OpenCVE Enrichment