Impact
A flaw in the Oracle Coherence component exposes a low‑privileged attacker who can reach the service over HTTP to trigger a partial denial of service. Based on the description, it is inferred that confidentiality and integrity are not compromised; the impact is limited to a reduction in service availability. The weakness can be classified as a service flaw (CWE‑400).
Affected Systems
Oracle Corporation’s Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, are affected. These editions are part of Oracle Fusion Middleware and are commonly deployed in clustered or distributed configurations in enterprise environments.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity based on availability impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, requiring only HTTP access over the network; no authentication is needed. An attacker with low privileges could easily trigger the flaw by sending crafted service disruption in the affected Coherence cluster.
OpenCVE Enrichment