Unauthenticated Network Vulnerability in Oracle Coherence
CVE-2022-21420
9.8CRITICAL
What is CVE-2022-21420?
A vulnerability exists in the Oracle Coherence component of Oracle Fusion Middleware that allows an unauthenticated attacker to gain access via the T3 protocol. This security flaw permits unauthorized control over the affected systems, potentially leading to a full compromise of Oracle Coherence instances. The vulnerability affects specific versions, making it essential for users to review their current deployments and apply necessary security patches to mitigate the associated risks.
Affected Version(s)
Coherence 12.2.1.3.0
Coherence 12.2.1.4.0
Coherence 14.1.1.0.0