Impact
The vulnerability resides in the core component of Oracle Coherence version 15.1.1.0.0 and allows an attacker who has logged on to the infrastructure where Coherence runs to read a subset of data exposed by the application. Because the technical flaw only permits limited confidential information to be accessed, the confidentiality impact is classified as low, yet the compromise could reveal sensitive or business logic data that may be valuable to an adversary. This vulnerability, identified as CWE-200, is a confidentiality exposure.
Affected Systems
Oracle Coherence 15.1.1.0.0, part of Oracle Fusion Middleware. The affected component is the Core module of the product.
Risk and Exploitability
The CVSS score of 2.5 reflects a low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is exploitable only from a logged‑on local session (Attack Vector: Local, Privileges: Low) and requires the attacker to have some level of access to the environment where Coherence runs. The vulnerability does not allow code execution or interruption of service; it is limited to unauthorized read of a limited data set. The product is not listed in the CISA KEV catalog, which further suggests that the publicly known exploitation of this weakness is unlikely at present.
OpenCVE Enrichment