cbcvebase.

Oracle Coherence vulnerabilities

115 known vulnerabilities affecting oracle/coherence.

Total CVEs
115
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL67HIGH30MEDIUM18

Vulnerabilities

Page 1 of 6
CVE-2020-2555P1CRITICALCVSS 9.8KEVPoCv3.7.1.0v12.1.3.0.0+2 more2020-01-15
CVE-2020-2555 [CRITICAL] CWE-502 CVE-2020-2555: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheS Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks o
nvd
CVE-2020-14756P1CRITICALCVSS 9.8ExploitedPoCv3.7.1.0v12.1.3.0.0+3 more2021-01-20
CVE-2020-14756 [CRITICAL] CVE-2020-14756: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Component Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of
nvd
CVE-2026-60217P2CRITICALCVSS 10.0v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60217 [CRITICAL] CWE-306 CVE-2026-60217: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coh
nvd
CVE-2026-35307P2CRITICALCVSS 10.0v12.2.1.4.0v14.1.1.0.0+2 more2026-06-17
CVE-2026-35307 [CRITICAL] CWE-284 CVE-2026-35307: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Co
nvd
CVE-2026-60242P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02026-07-21
CVE-2026-60242 [CRITICAL] CWE-306 CVE-2026-60242: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2026-60247P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.02026-07-21
CVE-2026-60247 [CRITICAL] CWE-306 CVE-2026-60247: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2026-35308P2CRITICALCVSS 10.0v12.2.1.4.0v14.1.1.0.0+2 more2026-06-17
CVE-2026-35308 [CRITICAL] CWE-284 CVE-2026-35308: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Th Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vuln
nvd
CVE-2026-60225P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60225 [CRITICAL] CWE-284 CVE-2026-60225: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerabilit
nvd
CVE-2026-60288P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60288 [CRITICAL] CWE-306 CVE-2026-60288: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60216P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60216 [CRITICAL] CWE-306 CVE-2026-60216: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60236P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60236 [CRITICAL] CWE-306 CVE-2026-60236: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60285P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60285 [CRITICAL] CWE-306 CVE-2026-60285: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60209P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60209 [CRITICAL] CWE-306 CVE-2026-60209: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60229P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60229 [CRITICAL] CWE-306 CVE-2026-60229: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60240P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60240 [CRITICAL] CWE-306 CVE-2026-60240: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60197P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60197 [CRITICAL] CWE-306 CVE-2026-60197: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60215P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60215 [CRITICAL] CWE-306 CVE-2026-60215: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60287P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60287 [CRITICAL] CWE-306 CVE-2026-60287: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60297P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60297 [CRITICAL] CWE-306 CVE-2026-60297: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60300P2CRITICALCVSS 9.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60300 [CRITICAL] CWE-306 CVE-2026-60300: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
Oracle Coherence vulnerabilities | cvebase