Impact
A missing authentication flaw (CWE‑306) in Oracle Coherence’s Core component enables an unauthenticated attacker who can reach the internal TCP port to take full control of the Coherence service.
Affected Systems
Oracle Corporation’s Coherence product is affected. The vulnerable component is Core, and the supported versions that contain this flaw are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
Based on the description, it is inferred that the attacker could use a network session to the exposed TCP port. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the CVSS 3.1 base score of 9.8 signals a high‑severity risk. The attack vector is a straightforward network‑based exploitation via a TCP port that is exposed within an internal network, requiring no authentication or privileged access. Any host with network reachability to the vulnerable port can potentially exploit the flaw.
OpenCVE Enrichment