Impact
The Oracle Coherence product is vulnerable to an unauthenticated network attack (CWE-306: Missing Authentication) that allows an adversary to take over the entire Coherence service, compromising confidentiality, integrity, and availability. The vulnerability is easily exploitable through a TCP connection without authentication, giving the attacker control over the affected instance.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and are widely deployed in enterprise environments.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that exploitation is currently rare, but the vulnerability is not listed in the CISA KEV catalog, meaning no known widespread exploits have been observed yet. Based on the description, the likely attack vector is an unauthenticated network connection over TCP, and the impact includes complete compromise of the target system.
OpenCVE Enrichment