Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, a component of Oracle Fusion Middleware, contains a vulnerability that allows an attacker with low privileges to send crafted TCP requests and cause the application to hang or crash, resulting in a complete denial of service. The flaw is classified as a low privileged attack that can be performed over the network, leveraging the public interfaces of the software. The impact focuses exclusively on availability, as stated by the CVSS vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, with no compromise of confidentiality or integrity.

Affected Systems

Affected versions are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. These releases are part of Oracle Fusion Middleware and are listed in the known CPE strings provided. Users running any of these versions should verify their current installation.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity focused on availability. The EPSS score is below 1%, indicating that the overall likelihood of exploitation in the wild is low, and the vulnerability is not currently listed in the CISA KEV catalog, reducing evidence of active exploitation. Nonetheless, because the exploitation requires only network access and low privilege, a determined attacker could repeatedly trigger crashes, which is why the higher impact of a compromised service should not be underestimated.

Generated by OpenCVE AI on August 4, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 patch to Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0
  • Configure network firewalls to restrict TCP access to Coherence ports to trusted hosts only
  • Enable comprehensive logging and monitoring for abnormal connection attempts that could lead to hangs or crashes

Generated by OpenCVE AI on August 4, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Network-Exploitable Denial of Service in Oracle Coherence

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Attack Enables Denial of Service in Oracle Coherence

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Attack Enables Denial of Service in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:55:43.659Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60243

cve-icon Vulnrichment

Updated: 2026-07-23T16:55:39.956Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption