Impact
A flaw in the core component of Oracle Coherence permits an unauthenticated attacker over a network TCP connection to induce a hang or repeatable crash, resulting in a complete denial of service to the affected system. This vulnerability is an instance of resource exhaustion weaknesses, identified as CWE-400. The vulnerability has a CVSS 3.1 Base Score of 7.5 with a vector highlighting Availability impact and indicates that only network access is required without privilege or user interaction.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. All deployments of these versions that expose Coherence services to a network should be reviewed.
Risk and Exploitability
The EPSS score of less than 1% suggests exploitation probability is currently low, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the CVSS score, the ability to do so without authentication, and the straightforward network attack vector make it a high‑priority risk for exposed Coherence deployments. An attacker who can connect to the relevant service can trigger a crash, causing application downtime until restarted.
OpenCVE Enrichment