Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The alert describes a vulnerability in the core component of Oracle Coherence that allows a low-privileged attacker who can reach the Coherence service over HTTP to read a restricted subset of data. The weakness is an information-exposure flaw documented as CWE-200. The CVSS vector indicates that confidentiality is impacted while integrity and availability are unaffected. Based on the description, it is inferred that no additional authentication beyond network access is required for exploitation, and the vulnerability does not alter the integrity or availability of the service.

Affected Systems

The affected product is Oracle Coherence from Oracle Corporation. The vulnerable releases are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, all part of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 classifies the vulnerability as low severity, focusing solely on confidentiality. The EPSS score is reported as less than 1 %, meaning that exploitation likelihood is very low. The flaw can be leveraged by any entity that has network access to the HTTP endpoint used by Coherence; no privileges beyond low are required. Based on the description, it is inferred that authentication is not required and that the vulnerability does not impact integrity or availability. Because the flaw is not listed in the CISA KEV catalog, it is not currently a known target for widespread attacks. Nonetheless, the potential for data exfiltration exists if the service is exposed to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Limit HTTP access to Coherence servers to trusted networks or use VPN/firewall rules to restrict exposure only to authorized hosts.
  • Enforce strong authentication and role-based access controls on Coherence services to prevent unauthorized data reads.
  • Implement network segmentation and monitoring for unusual access patterns to Coherence endpoints, and apply intrusion detection rules to alert on potential data exfiltration attempts.

Generated by OpenCVE AI on August 4, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Information Exposure via HTTP in Oracle Coherence Enables Unauthorized Data Read

Sat, 01 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Information Exposure via HTTP in Oracle Coherence Enables Unauthorized Data Read

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTP in Oracle Coherence
Weaknesses CWE-285

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via HTTP in Oracle Coherence
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:40:02.887Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60307

cve-icon Vulnrichment

Updated: 2026-07-23T18:39:55.328Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor