Impact
The core component of Oracle Coherence is vulnerable to a network‑level weakness that allows an attacker with low privileges and HTTP access to gain full control of the Coherence service. Successful exploitation can result in a compromise that affects confidentiality, integrity, and availability, effectively taking over the Coherence deployment.
Affected Systems
Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. These versions are part of Oracle Fusion Middleware and, based on the description, it is inferred that they may be deployed in a variety of environments, including public and private clouds.
Risk and Exploitability
The CVSS 3.1 vector indicates remote network access, high attack complexity and low privileges, yet the impact is complete control of the service. With an EPSS score of less than 1%, the current risk of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack path likely involves an unprotected HTTP management interface that the attacker can remotely access without authentication.
OpenCVE Enrichment