Impact
This vulnerability in the Oracle Coherence Core component leverages improper privilege management (CWE-269) to allow an attacker with low privileges and network access via HTTP to gain unauthorized control. The flaw permits unauthorized execution of privileged operations and ultimately full takeover of the Coherence cluster, resulting in total loss of confidentiality, integrity, and availability. By exploiting this weakness, a remote attacker can perform any actions that the privileged user can, up to full cluster compromise, without requiring additional credentials.
Affected Systems
Oracle Coherence, versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, are affected. These are provided as part of Oracle Fusion Middleware. No other products or releases are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 marks this as high severity. Its EPSS score is below 1%, meaning the current exploitation probability is low, and it is not listed in the CISA KEV catalog. Nevertheless, the flaw is remotely exploitable over an open HTTP interface and requires only low privileges, so exposed systems remain at significant risk of immediate takeover.
OpenCVE Enrichment