Impact
The vulnerability in Oracle Coherence 15.1.1.0.0 allows a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in unauthorized access to critical data or full access to all data accessible within Oracle Coherence, and may impact other Fusion Middleware components due to a scope change.
Affected Systems
The affected product is Oracle Coherence from Oracle Corporation, version 15.1.1.0.0. No other vendors or product versions are listed as vulnerable in the CNA data.
Risk and Exploitability
The CVSS v3.1 base score of 6.3 indicates a medium severity with a confidentiality impact and a scope change. The EPSS score is less than 1%, showing a low but nonzero exploitation probability in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based via HTTP, requiring only low privileges and no user interaction. Given the moderate severity score and low EPSS, the overall risk is moderate; however, the potential to compromise sensitive data warrants prompt remedial action.
OpenCVE Enrichment