Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence is vulnerable to a weakness that allows an unauthenticated attacker with network access through HTTP to modify, insert or delete data, as well as read restricted data. The flaw is in the Coherence Core component and results in both confidentiality and integrity impacts, but does not affect availability. The CVSS 3.1 base score is 5.4, reflecting moderate severity with low confidentiality and integrity impacts.

Affected Systems

The affected systems are Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all part of Oracle Fusion Middleware. These versions are listed by Oracle as impacted and may expose the mentioned data through the Coherence HTTP interface.

Risk and Exploitability

The risk of exploitation is low in terms of likelihood, as indicated by an EPSS score of less than 1%. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely remote over the network, requiring no authentication and accessed via HTTP. If successful, the attacker can obtain or alter data accessible to Coherence, potentially affecting downstream applications that rely on this data. Given the moderate CVSS score and low EPSS, the immediate risk is moderate, though an exposed endpoint could be leveraged to compromise other product components, as denoted by the scope change statement.

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit external HTTP access to Oracle Coherence by restricting allowed IP ranges or placing it behind a firewall or VPN
  • Apply any Oracle‑issued patch or upgrade to a version that includes the fix once available
  • Verify that the network configuration for Coherence forbids unauthenticated HTTP traffic and monitor for suspicious activity

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Data Modification and Read in Oracle Coherence

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Data Modification and Read in Oracle Coherence

Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Data Exposure via HTTP in Oracle Coherence
Weaknesses CWE-200

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Data Exposure via HTTP in Oracle Coherence
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Coherence accessible data as well as unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:50:18.345Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60238

cve-icon Vulnrichment

Updated: 2026-07-23T16:48:00.628Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses