Impact
A local privilege vulnerability in Oracle Coherence allows an attacker who already has high privileged access to the underlying infrastructure to alter data stored within the Coherence cluster. The flaw does not enable code execution or affect confidentiality; its sole impact is to permit unauthorized updates, insertions, or deletions of data accessible through Coherence.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected.
Risk and Exploitability
The CVSS score of 1.9 reflects a low severity with only integrity impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation observed in the wild. It is not listed in the CISA KEV catalog, and no publicly available exploit was reported. The vulnerability can only be exploited by a user who has already logged on with sufficient privileges to the machine running Coherence, so it is a local attack vector requiring local access and administrative rights.
OpenCVE Enrichment