Impact
A flaw in Oracle Coherence allows an unauthenticated attacker to send specially crafted TCP packets that are interpreted as commands, leading to takeover of Oracle Coherence. The vulnerability is classified as a high‑impact flaw, with a CVSS 3.1 Base Score of 9.8, indicating that successful exploitation would compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are commonly deployed as part of Oracle Fusion Middleware in enterprise environments.
Risk and Exploitability
The flaw can be exploited remotely over the network, requiring only TCP connectivity and no authentication. The EPSS score of less than 1% suggests that the likelihood of a real‑world exploit is currently low, but the absence of the vulnerability from the CISA KEV catalog does not mitigate the high potential impact. Attackers would need to construct and transmit malicious packets that exploit the authentication weakness highlighted by CWE‑306.
OpenCVE Enrichment