Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data and unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Coherence 15.1.1.0.0 permits an attacker without authentication to send crafted TCP traffic that can cause the application to hang or crash repeatedly, leading to complete denial of service. In addition, the same vulnerability allows unauthorized updates, inserts, deletes, and reads of data exposed by the Coherence service, compromising both confidentiality and integrity of that data.

Affected Systems

Oracle Corporation’s Coherence product, version 15.1.1.0.0, is the only affected version listed. No other Oracle Fusion Middleware components or product versions are currently reported as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 8.6 indicates high severity with moderate confidentiality and integrity impact but high availability impact. EPSS indicates an extremely low likelihood of exploitation in the field (<1%). The vulnerability is not yet listed in CISA’s KEV catalog, suggesting no known active exploitation currently. Attack requires only network access to the Coherence TCP port and no authentication, making the threat vector easily exploitable by any remote endpoint capable of establishing a TCP connection to the target system.

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle 15.1.1.0.0 security patch released in the July 2026 CPU as detailed in the Oracle security alert
  • Restrict or firewall the Coherence TCP ports to trusted internal networks or VPNs to prevent unauthenticated external access
  • Review Coherence configuration to enforce authentication and authorization mechanisms and ensure that sensitive data is not exposed through unsecured interfaces

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service and Data Tampering in Oracle Coherence via TCP
Weaknesses CWE-200
CWE-287
CWE-416
CWE-862

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service and Data Tampering in Oracle Coherence via TCP
Weaknesses CWE-200
CWE-287
CWE-416
CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data and unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:43:51.315Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60235

cve-icon Vulnrichment

Updated: 2026-07-23T15:43:42.475Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function