Impact
The vulnerability in Oracle Coherence, identified as CWE‑306 (Missing Authentication for Critical Function), allows an unauthenticated attacker with network access via HTTP to compromise the application, effectively taking full control of the Coherence instance. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a high confidence that exploitation can lead to confidential data disclosure, integrity violations, and complete availability loss, reflecting a full compromise of the system.
Affected Systems
Affected systems are Oracle Corporation’s Coherence component of Oracle Fusion Middleware. The versions subject to the flaw are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These versions are supported under Oracle’s product lifecycle and are routinely accessed over HTTP interfaces.
Risk and Exploitability
The CVSS score of 9.8 marks the issue as critical, but the EPSS score of less than 1% indicates that current exploitation activity is low despite the severity. Since the vulnerability is listed as not in CISA’s KEV catalog, no known public exploits are currently documented. The likely attack vector is an unauthenticated HTTP request to exposed Coherence endpoints, with no privilege requirement or user interaction needed. If exploited, an attacker gains total control over the affected instance, enabling data exfiltration, tampering, or service disruption.
OpenCVE Enrichment