Impact
Easily exploitable vulnerability in Oracle Coherence allows an unauthenticated attacker to fully compromise the system with network access via HTTP, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Coherence product is affected, specifically versions 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Risk and Exploitability
The CVSS score of 9.8 signifies a critical severity. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can reach the vulnerable component over the public or internal network via HTTP, with no authentication required, and exploit it to gain full control of the Coherence cluster.
OpenCVE Enrichment