Impact
The CVE describes a flaw in Oracle Coherence’s core component that enables an unauthenticated attacker with network access via HTTP to compromise the service. This missing authentication weakness (CWE-306) allows the attacker to bypass usual credential checks. Successful exploitation can result in a full takeover of Oracle Coherence, with severe impacts on confidentiality, integrity and availability as reflected in the CVSS 3.1 vector.
Affected Systems
Oracle Coherence from Oracle Corporation is affected. The vulnerable releases are 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, if the default HTTP interface is reachable from the network.
Risk and Exploitability
The CVSS score of 9.8 places this finding in the "Critical" severity band, and the EPSS score of less than 1 % indicates that real-world exploitation is currently low, though the vulnerability remains high risk. The vulnerability is not listed in the CISA KEV catalog. The attack vector is over a network connection to an HTTP endpoint and does not require prior authentication, as stated in the description.
OpenCVE Enrichment