Security readout for executives and security teams
Plain-English summary
This is a high-severity Oracle Coherence flaw where an unauthenticated network attacker using HTTP could read critical data. The business risk is data exposure from affected Coherence deployments, not system takeover or service outage based on the published CVSS impact.
Executive priority
Prioritize remediation for internet-facing or business-critical Coherence deployments because the flaw can expose critical data without authentication. Internal-only systems still warrant action if they process sensitive data or are reachable by broad user networks.
Technical view
CVE-2021-2277 affects Oracle Coherence Core versions 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The CVSS vector is network exploitable, low complexity, no privileges, no user interaction, with high confidentiality impact only.
Likely exposure
Exposure is most likely where Oracle Coherence HTTP-accessible services are reachable from untrusted networks or insufficiently segmented internal networks. Organizations using Oracle Fusion Middleware stacks should verify whether Coherence is present and at an affected version.
Exploitation context
The provided sources do not show CISA KEV listing or active exploitation evidence. The vulnerability is described as easily exploitable over HTTP without authentication, so exposed services should be treated as sensitive even without confirmed exploitation.
Researcher notes
No CWE is supplied in the source bundle, and public details here do not describe the vulnerable code path. Assessment should stay focused on version exposure, HTTP reachability, confidentiality impact, and Oracle advisory alignment.
Mitigation direction
- Apply Oracle Critical Patch Update guidance for April 2021 or later supported fixes.
- Identify and upgrade affected Oracle Coherence versions where present.
- Restrict HTTP access to Coherence services to trusted networks only.
- Use compensating network controls until vendor remediation is confirmed.
Validation and detection
- Inventory Oracle Coherence deployments and record exact versions.
- Check whether affected versions are still running in production or staging.
- Confirm Oracle CPU remediation status with patch records.
- Review network paths exposing Coherence HTTP interfaces.
- Inspect logs for unusual unauthenticated HTTP access patterns.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-2277 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuapr2021.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
