Impact
A TCP‑based vulnerability in Oracle Coherence’s Core component can be triggered by an attacker with low privileges and network access, enabling the craft of specific traffic that causes the service to hang or crash repeatedly. The flaw is an instance of Improper Access Control (CWE‑284) and results in a complete denial of service, with no direct compromise of data or elevation of privileges.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 from Oracle Corporation are affected. Any deployment of these releases that is reachable over the network exposes the service to this vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity with a significant availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be carried out over an unauthenticated TCP connection and does not require elevated privileges, making the attack vector relatively easy for an attacker with network access.
OpenCVE Enrichment