Impact
A flaw in Oracle Coherence, a component of Oracle Fusion Middleware, allows an unauthenticated attacker with network access via TCP to take full control of the application. This easily exploitable vulnerability can result in takeover, compromising confidentiality, integrity, and availability. The weakness is a lack of authentication, mapping to CWE-306.
Affected Systems
Affected products include Oracle Coherence from Oracle Corporation. The impacted releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS 3.1 Base Score of 9.8 indicates a critical risk. The EPSS score is below 1 %, suggesting a low probability of exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote TCP connection, unauthenticated, exploiting a core component that permits full compromise.
OpenCVE Enrichment