Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence is a distributed caching and data sharing component of Oracle Fusion Middleware. A flaw in its Core component allows an unauthenticated attacker to influence the application through HTTP requests. Successful exploitation can cause the system to hang or crash repeatedly, resulting in a denial of service, and can also permit unauthorized insertion, update, or deletion of cached data. The flaw involves resource exhaustion (CWE‑400), producing tangible integrity and availability impacts without affecting confidentiality.

Affected Systems

Affected versions are Oracle Coherence 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All are supported release streams commonly deployed across production environments that rely on Coherence for high‑availability caching and distributed data structures.

Risk and Exploitability

The CVSS base score of 6.5 signifies a moderate risk level, while the EPSS score of less than 1% indicates current exploitation activity is not widely observed. The vulnerability is not listed in the CISA KEV catalog, but it remains a serious risk where Coherence is exposed to external networks. Based on the description, the likely attack vector is network access through the exposed HTTP interface, which requires no authentication. Exploitation involves sending crafted HTTP requests that trigger exceptions or memory exhaustion, leading to repeated service crashes and unauthorized data changes. The combination of availability loss and integrity compromise makes this a high‑impact threat for organizations that depend on Coherence for critical services.

Generated by OpenCVE AI on August 4, 2026 at 17:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Coherence 14.1.1.0.0, 14.1.2.0.0, or 15.1.1.0.0 released in the Oracle CPU July 2026 advisory.
  • If a patch cannot be applied immediately, limit HTTP connectivity to Coherence to trusted hosts or internal IP ranges, effectively exposing the service only to authorized network segments.
  • Enforce strict application‑level access controls to guard against unauthorized write operations, and enable detailed logging of data modification requests to facilitate forensic analysis.

Generated by OpenCVE AI on August 4, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP DoS and Data Modification in Oracle Coherence

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP DoS and Data Modification in Oracle Coherence

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Vulnerability Enables Unauthorized Data Modification and Denial of Service via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Oracle Coherence Vulnerability Enables Unauthorized Data Modification and Denial of Service via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:56:54.368Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60213

cve-icon Vulnrichment

Updated: 2026-07-23T15:56:43.069Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption