Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle Coherence 15.1.1.0.0 is an easily exploitable network vulnerability that permits a low‑privileged attacker with TCP access to compromise the core component and force a temporary loss of service availability. The weakness, described by CWE-400, is improper handling of inbound traffic that can trigger resource exhaustion, leading to a partial denial of service with no compromise to confidentiality or integrity. The impact is limited to service disruption rather than data exfiltration or code execution.

Affected Systems

Oracle Coherence, part of Oracle Fusion Middleware, is affected when running version 15.1.1.0.0. This is the only version explicitly listed as vulnerable in the Oracle information.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 indicates a moderate severity with availability impact only. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild, and the vulnerability is not included in CISA’s KEV catalog. Attackers need network access to the Coherence cluster and can achieve the denial of service from a low‑privileged account, but no privileged escalation or data compromise is required. Overall risk is moderate but the probability of successful exploitation remains low.

Generated by OpenCVE AI on August 2, 2026 at 23:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch released in CPU Jul 2026 for CVE-2026-60233
  • Restrict TCP ports used by Oracle Coherence to trusted hosts using firewall rules or network segmentation
  • Monitor Coherence logs for abnormal connection patterns and block offending IPs if DoS activity is detected

Generated by OpenCVE AI on August 2, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Network Exploit in Oracle Coherence 15.1.1.0.0

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Denial of Service in Oracle Coherence via TCP

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Denial of Service in Oracle Coherence via TCP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:46:51.155Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60233

cve-icon Vulnrichment

Updated: 2026-07-23T15:46:40.791Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption