Impact
A flaw in Oracle Coherence allows an attacker with low privileges who can reach the system over HTTP to trigger a partial denial of service. The weakness leads to availability impact only, without exposing sensitive data or enabling arbitrary code execution.
Affected Systems
Oracle Coherence (Oracle Fusion Middleware). Vulnerable versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 4.3, reflecting a moderate risk confined to availability. The EPSS score is less than 1%, indicating a very low probability of exploitation. It is not listed in CISA KEV. Exploitation requires only network connectivity to the vulnerable HTTP endpoints and does not rely on elevated privileges or specialized tools.
OpenCVE Enrichment