Oracle Coherence vulnerabilities
115 known vulnerabilities affecting oracle/coherence.
Total CVEs
115
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL67HIGH30MEDIUM18
Vulnerabilities
Page 4 of 6
CVE-2020-2915P2CRITICALCVSS 9.8v3.7.1.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2915 [CRITICAL] CVE-2020-2915: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, Cache
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks o
nvd
CVE-2026-60239P2CRITICALCVSS 9.6v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60239 [CRITICAL] CWE-284 CVE-2026-60239: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coh
nvd
CVE-2026-60267P2CRITICALCVSS 9.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60267 [CRITICAL] CWE-284 CVE-2026-60267: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2022-21420P2CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.0+1 more2022-04-19
CVE-2022-21420 [CRITICAL] CVE-2022-21420: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeo
nvd
CVE-2026-60268P3HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60268 [HIGH] CWE-284 CVE-2026-60268: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60218P3HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60218 [HIGH] CWE-306 CVE-2026-60218: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60220P3CRITICALCVSS 9.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60220 [CRITICAL] CWE-284 CVE-2026-60220: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks require human interac
nvd
CVE-2020-25649P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02020-12-03
CVE-2020-25649 [HIGH] CWE-611 CVE-2020-25649: A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured prope
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
nvd
CVE-2026-60235P3HIGHCVSS 8.6v15.1.1.0.02026-07-21
CVE-2026-60235 [HIGH] CWE-306 CVE-2026-60235: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The s
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2026-60295P3HIGHCVSS 8.5v14.1.1.0.0v14.1.2.0.0+1 more2026-07-21
CVE-2026-60295 [HIGH] CWE-284 CVE-2026-60295: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks
nvd
CVE-2026-60222P3HIGHCVSS 8.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60222 [HIGH] CWE-284 CVE-2026-60222: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerabil
nvd
CVE-2026-60277P3HIGHCVSS 8.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60277 [HIGH] CWE-306 CVE-2026-60277: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability c
nvd
CVE-2026-60273P3HIGHCVSS 8.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60273 [HIGH] CWE-306 CVE-2026-60273: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability c
nvd
CVE-2026-60248P3CRITICALCVSS 9.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60248 [CRITICAL] CWE-269 CVE-2026-60248: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Whi
nvd
CVE-2026-60211P3HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60211 [HIGH] CWE-284 CVE-2026-60211: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence ex
nvd
CVE-2026-60284P3HIGHCVSS 8.2v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60284 [HIGH] CWE-284 CVE-2026-60284: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability ca
nvd
CVE-2026-60249P3CRITICALCVSS 9.0v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60249 [CRITICAL] CWE-284 CVE-2026-60249: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence
nvd
CVE-2026-60261P3HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60261 [HIGH] CWE-284 CVE-2026-60261: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence ex
nvd
CVE-2026-60309P3HIGHCVSS 8.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60309 [HIGH] CWE-284 CVE-2026-60309: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence ex
nvd
CVE-2026-60214P3HIGHCVSS 8.7v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60214 [HIGH] CWE-284 CVE-2026-60214: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence exe
nvd