Impact
A flaw in Oracle Coherence’s Core component permits an unauthenticated user who can reach the system via TCP to compromise the application, resulting in full takeover. The vulnerability is caused by missing authentication (CWE‑306).
Affected Systems
Oracle Corporation’s Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and are deployed in many enterprise applications.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 demonstrates a critical risk. EPSS indicates the likelihood of exploitation is below 1%, suggesting low probability of widespread attacks at this moment, but the potential for catastrophic compromise remains. The vulnerability is not listed in CISA KEV. Exploitation requires only network access and no authentication, making it highly attractive to adversaries targeting internal networks.
OpenCVE Enrichment