Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the core component of Oracle Coherence permits an unauthenticated attacker over a network TCP connection to induce a hang or repeatable crash, resulting in a complete denial of service to the affected system. This vulnerability is an instance of resource exhaustion weaknesses, identified as CWE-400. The vulnerability has a CVSS 3.1 Base Score of 7.5 with a vector highlighting Availability impact and indicates that only network access is required without privilege or user interaction.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. All deployments of these versions that expose Coherence services to a network should be reviewed.

Risk and Exploitability

The EPSS score of less than 1% suggests exploitation probability is currently low, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the CVSS score, the ability to do so without authentication, and the straightforward network attack vector make it a high‑priority risk for exposed Coherence deployments. An attacker who can connect to the relevant service can trigger a crash, causing application downtime until restarted.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or upgrade to a non‑affected version as detailed in Oracle’s CPU July 2026 advisory.
  • If a patch cannot be applied immediately, block unauthenticated inbound TCP traffic to the Coherence service using a firewall or network ACL.
  • Continuously monitor Coherence logs and service status for crashes or hangs and restart the service automatically when detected.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network DoS via Coherence Resource Exhaustion

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network DoS via Coherence Resource Exhaustion

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote DoS via TCP in Oracle Coherence
Weaknesses CWE-399

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote DoS via TCP in Oracle Coherence
Weaknesses CWE-399

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:46:44.180Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60301

cve-icon Vulnrichment

Updated: 2026-07-23T18:46:06.552Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption