Impact
A vulnerability in Oracle Coherence’s core component makes it possible for an attacker with low privileges who can reach the service over TCP to compromise the Coherence cluster. The flaw is considered difficult to exploit, but once triggered it allows the attacker to take over the Coherence component, potentially leading to loss of confidentiality, integrity, and availability. Because the vulnerability is in a core component, the impact may actually extend beyond Coherence to other applications that rely on it, changing the affected scope.
Affected Systems
The affected versions are Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all released under Oracle Corporation’s Fusion Middleware umbrella. No further vendor or product information is provided beyond the Oracle Coherence listing.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 indicates a high‑severity flaw. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the vulnerability is reachable over the network, requires only low privileges, and its exploit can lead to full takeover of the component. Attackers would need access to the internal network or be able to reach the TCP ports that expose Coherence; there is no mention of user interaction or fallback defenses.
OpenCVE Enrichment