Oracle Coherence vulnerabilities
16 known vulnerabilities affecting oracle/coherence.
Total CVEs
16
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH9MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-21570HIGHCVSS 7.5v3.7.1.0v12.2.1.3.0+2 more2022-07-19
CVE-2022-21570 [HIGH] CVE-2022-21570: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can resu
nvd
CVE-2022-21420CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.0+1 more2022-04-19
CVE-2022-21420 [CRITICAL] CVE-2022-21420: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeo
nvd
CVE-2020-36518HIGHCVSS 7.5v14.1.1.0.02022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2021-43797MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.02021-12-09
CVE-2021-43797 [MEDIUM] CWE-444 CVE-2021-43797: Netty is an asynchronous event-driven network application framework for rapid development of maintai
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead
nvd
CVE-2021-37136HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02021-10-19
CVE-2021-37136 [HIGH] CWE-400 CVE-2021-37136: The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
nvd
CVE-2021-2371HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2371 [HIGH] CVE-2021-2371: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerabilit
nvd
CVE-2021-2344HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2344 [HIGH] CVE-2021-2344: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerabilit
nvd
CVE-2021-2428HIGHCVSS 8.1v12.1.3.0.0v12.2.1.3.0+2 more2021-07-21
CVE-2021-2428 [HIGH] CVE-2021-2428: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can r
nvd
CVE-2021-2277HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-04-22
CVE-2021-2277 [HIGH] CVE-2021-2277: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability ca
nvd
CVE-2021-21409MEDIUMCVSS 5.9v12.2.1.4.0v14.1.1.0.02021-03-30
CVE-2021-21409 [MEDIUM] CWE-444 CVE-2021-21409: Netty is an open-source, asynchronous event-driven network application framework for rapid developme
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the requ
nvd
CVE-2020-14756CRITICALCVSS 9.8v3.7.1.0v12.1.3.0.0+3 more2021-01-20
CVE-2020-14756 [CRITICAL] CVE-2020-14756: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Component
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of
nvd
CVE-2020-25649HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02020-12-03
CVE-2020-25649 [HIGH] CWE-611 CVE-2020-25649: A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured prope
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
nvd
CVE-2020-14642HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2020-07-15
CVE-2020-14642 [HIGH] CWE-404 CVE-2020-14642: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). S
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this
nvd
CVE-2020-2915CRITICALCVSS 9.8v3.7.1.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2915 [CRITICAL] CVE-2020-2915: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, Cache
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks o
nvd
CVE-2020-2949MEDIUMCVSS 5.3v3.7.1.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2949 [MEDIUM] CVE-2020-2949: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, Cache
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this
nvd
CVE-2020-2555CRITICALCVSS 9.8KEVPoCv3.7.1.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2555 [CRITICAL] CWE-502 CVE-2020-2555: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheS
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks o
nvd