Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to trigger a hang or repeated crash of the Coherence service. The flaw is easily exploitable and can cause a complete denial of service, affecting only availability while no confidentiality or integrity impact has been reported. This flaw is a Resource Exhaustion vulnerability (CWE-400).

Affected Systems

Oracle Coherence from Oracle Corporation is impacted. The affected releases include version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. All these builds expose a remote TCP interface that can be abused without authentication.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high severity availability issue, and the EPSS score of less than 1% suggests the overall exploitation likelihood is currently low, though the vulnerability is still not listed in CISA KEV. The attack vector is likely a simple TCP connection to a known Coherence port, requiring no credentials. The probability of exploitation in the wild is low, and the impact of a successful attack is significant for environments that rely on Coherence for distributed caching or messaging.

Generated by OpenCVE AI on August 2, 2026 at 23:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence security update from the Oracle Critical Patch Updates for July 2026.
  • Block external TCP access to the Coherence service using firewall rules or network segmentation until the patch is applied.
  • Monitor Coherence service logs and system behavior for abnormal hang or crash events to detect exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 23:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Vulnerability Allowing Remote Denial of Service in Oracle Coherence

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service in Oracle Coherence via TCP

Mon, 27 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Denial of Service in Oracle Coherence via TCP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:00:52.154Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60252

cve-icon Vulnrichment

Updated: 2026-07-23T17:00:39.763Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption