
Cloud Vulnerability DB
A community-led vulnerabilities database
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data (Oracle Advisory).
The vulnerability has a CVSS 3.1 Base Score of 7.5 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. This indicates it is a network-exploitable vulnerability requiring no privileges or user interaction, affecting confidentiality but not integrity or availability (Oracle Advisory).
Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data. The high CVSS score of 7.5 indicates significant potential impact on data confidentiality (Oracle Advisory).
The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP. No special privileges or user interaction is required for exploitation (Oracle Advisory).
Oracle has released security patches for affected versions (3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0) as part of the April 2021 Critical Patch Update. Oracle strongly recommends that customers apply the security patches as soon as possible (Oracle Advisory).
The vulnerability was discovered and reported by Xianglai Liu of Dbappsecurity Team and Longofo of Knownsec 404 Team (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."