Impact
Oracle Coherence, a component of Oracle Fusion Middleware, suffers from an authentication bypass flaw that permits an attacker with access to the physical network segment attached to the hardware running Coherence to fully compromise the instance. The flaw lies in the Core component and allows the attacker to assume full control, jeopardizing confidentiality, integrity, and availability. This weakness maps to improper access control, as the software fails to enforce authentication on the local network interface.
Affected Systems
Oracle Coherence from Oracle Corporation is affected. Vulnerable versions are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates a high severity vulnerability that impacts the CIA triad. The EPSS score of <1% suggests that current exploitation probability is low, but the requirement of only local network access means an attacker with physical or network segment access can easily gain the necessary foothold. The CVE is not listed in CISA’s KEV catalog; however, the potential for full control of Oracle Coherence remains a serious threat within the local network context.
OpenCVE Enrichment