Impact
Oracle Coherence, part of Oracle Fusion Middleware, contains a vulnerability that permits a low privileged attacker with network access via TCP to create, delete, or modify data, and to read subsets of data that should be protected. The attack allows the attacker to alter or obtain critical data within the Coherence environment, undermining both the confidentiality and integrity of that data.
Affected Systems
The affected instances are Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact with confidentiality and integrity consequences. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a low privileged network attacker who can reach the Coherence service via TCP, making the exploitation relatively straightforward for anyone who can communicate with the target system.
OpenCVE Enrichment