Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-09-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Partial Denial of Service
Action: Deploy Mitigations
AI Analysis

Impact

A flaw in the Oracle Coherence component exposes a low‑privileged attacker who can reach the service over HTTP to trigger a partial denial of service. Based on the description, it is inferred that confidentiality and integrity are not compromised; the impact is limited to a reduction in service availability. The weakness can be classified as a service flaw (CWE‑400).

Affected Systems

Oracle Corporation’s Oracle Coherence, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, are affected. These editions are part of Oracle Fusion Middleware and are commonly deployed in clustered or distributed configurations in enterprise environments.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity based on availability impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, requiring only HTTP access over the network; no authentication is needed. An attacker with low privileges could easily trigger the flaw by sending crafted service disruption in the affected Coherence cluster.

Generated by OpenCVE AI on September 18, 2026 at 18:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict HTTP access to the Oracle Coherence service to trusted networks or VPNs to reduce exposure
  • Deploy rate limiting or a Web Application Firewall to mitigate repeated denial‑of‑service attempts
  • Monitor system logs for abnormal traffic patterns and apply updates when Oracle releases a fix

Generated by OpenCVE AI on September 18, 2026 at 18:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via HTTP in Oracle Coherence
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via HTTP in Oracle Coherence
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T16:14:27.961Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83416

cve-icon Vulnrichment

Updated: 2026-09-18T16:11:50.326Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:50.017

Modified: 2026-09-21T16:12:53.020

Link: CVE-2026-83416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption