Impact
Oracle Coherence, part of Oracle Fusion Middleware, has a vulnerability (CWE‑306: Missing Authentication for Critical Function) that allows an attacker with network access to connect via TCP and perform an unauthenticated takeover of the Coherence service. The flaw grants the attacker full control, enabling modification of data, execution of arbitrary code, and denial of service, affecting confidentiality, integrity, and availability. This issue is reflected in a CVSS v3.1 base score of 9.8, indicating critical severity.
Affected Systems
Vulnerable versions include Oracle Coherence 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These are supported releases and deploy the affected Core component. No additional operating systems or deployment specifics are listed in the advisory.
Risk and Exploitability
The vulnerability arises from missing authentication (CWE‑306), meaning an attacker requires only network connectivity to the exposed Coherence TCP port, with no credentials or local privilege escalation needed. The EPSS score is below 1%, suggesting low observed exploitation frequency, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS score and the nature of the flaw—requiring only network connectivity to the target port—make exploitation technically straightforward. Given the potential impact, the risk remains high for any environment where the Coherence service is reachable from untrusted networks.
OpenCVE Enrichment