Impact
Oracle Coherence has a flaw in its access‑control logic that can be exploited by a low‑privileged attacker with network connectivity over TCP. The vulnerability permits the creation, deletion, or modification of data stored in the Coherence cluster, as well as unauthorized read access to critical data. The impact is a loss of data confidentiality and integrity; availability is not affected. This weakness is classified as an improper authorization (CWE‑284).
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These releases are part of Oracle Fusion Middleware and are typically deployed in distributed in‑memory data grid environments. Any installation of these versions that exposes the Coherence service to the network is vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 illustrates a high severity for confidentiality and integrity due to a low privilege requirement and network‐based attack vector. The EPSS score of less than 1% indicates that, although easily exploitable, widespread exploitation is currently rare. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need only TCP connectivity to the Coherence cluster and can exploit the flaw without complex preparation, making it a realistic threat to deployments reachable from untrusted networks.
OpenCVE Enrichment