Impact
The alert describes a vulnerability in the core component of Oracle Coherence that allows a low-privileged attacker who can reach the Coherence service over HTTP to read a restricted subset of data. The weakness is an information-exposure flaw documented as CWE-200. The CVSS vector indicates that confidentiality is impacted while integrity and availability are unaffected. Based on the description, it is inferred that no additional authentication beyond network access is required for exploitation, and the vulnerability does not alter the integrity or availability of the service.
Affected Systems
The affected product is Oracle Coherence from Oracle Corporation. The vulnerable releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all part of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 classifies the vulnerability as low severity, focusing solely on confidentiality. The EPSS score is reported as less than 1 %, meaning that exploitation likelihood is very low. The flaw can be leveraged by any entity that has network access to the HTTP endpoint used by Coherence; no privileges beyond low are required. Based on the description, it is inferred that authentication is not required and that the vulnerability does not impact integrity or availability. Because the flaw is not listed in the CISA KEV catalog, it is not currently a known target for widespread attacks. Nonetheless, the potential for data exfiltration exists if the service is exposed to untrusted networks.
OpenCVE Enrichment