Impact
The defect in Oracle Coherence allows an attacker with low privileges and network access to several protocols to take control of the Coherence instance. The vulnerability enables remote code execution, granting the threat actor full control over the target system, with the ability to read, modify, or delete data and to disrupt services. The weakness is consistent with an improper privilege management flaw.
Affected Systems
Oracle Corporation’s Oracle Coherence product is affected. The specific versions that are vulnerable include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are part of Oracle Fusion Middleware and rely on the Core component for distributed caching and data management.
Risk and Exploitability
The CVSS base score of 8.8 places this vulnerability in the high severity range. The EPSS score of less than 1% indicates that, at the time of analysis, the probability of exploitation in the wild is low, and the vulnerability is not catalogued in CISA’s KEV list. Nonetheless, the attack vector is inferred to be remote, requiring network connectivity to Coherence services and potentially low‑privilege credentials, but no user interaction or elevated privileges. Successful exploitation can result in complete takeover of the affected system, with full confidentiality, integrity, and availability compromise.
OpenCVE Enrichment