Oracle Coherence vulnerabilities
115 known vulnerabilities affecting oracle/coherence.
Total CVEs
115
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL67HIGH30MEDIUM18
Vulnerabilities
Page 5 of 6
CVE-2021-2428P3HIGHCVSS 8.1v12.1.3.0.0v12.2.1.3.0+2 more2021-07-21
CVE-2021-2428 [HIGH] CVE-2021-2428: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can r
nvd
CVE-2026-60255P3HIGHCVSS 8.2v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60255 [HIGH] CWE-306 CVE-2026-60255: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60263P3HIGHCVSS 7.5v14.1.1.0.0v14.1.2.0.0+1 more2026-07-21
CVE-2026-60263 [HIGH] CWE-306 CVE-2026-60263: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in u
nvd
CVE-2026-60281P3HIGHCVSS 8.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60281 [HIGH] CWE-284 CVE-2026-60281: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence ex
nvd
CVE-2021-2277P3HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-04-22
CVE-2021-2277 [HIGH] CVE-2021-2277: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability ca
nvd
CVE-2026-60301P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60301 [HIGH] CWE-400 CVE-2026-60301: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60252P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60252 [HIGH] CWE-400 CVE-2026-60252: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60223P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60223 [HIGH] CWE-284 CVE-2026-60223: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60271P3HIGHCVSS 7.8v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60271 [HIGH] CWE-269 CVE-2026-60271: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Successf
nvd
CVE-2020-14642P3HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2020-07-15
CVE-2020-14642 [HIGH] CWE-404 CVE-2020-14642: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). S
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this
nvd
CVE-2021-2344P3HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2344 [HIGH] CVE-2021-2344: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerabilit
nvd
CVE-2021-2371P3HIGHCVSS 7.5v3.7.1.0v12.1.3.0.0+3 more2021-07-21
CVE-2021-2371 [HIGH] CVE-2021-2371: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerabilit
nvd
CVE-2022-21570P3HIGHCVSS 7.5v3.7.1.0v12.2.1.3.0+2 more2022-07-19
CVE-2022-21570 [HIGH] CVE-2022-21570: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Support
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can resu
nvd
CVE-2021-37136P3HIGHCVSS 7.5v12.2.1.4.0v14.1.1.0.02021-10-19
CVE-2021-37136 [HIGH] CWE-400 CVE-2021-37136: The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
nvd
CVE-2026-60305P3HIGHCVSS 7.1v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60305 [HIGH] CWE-284 CVE-2026-60305: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can
nvd
CVE-2026-60213P3MEDIUMCVSS 6.5v14.1.1.0.0v14.1.2.0.0+1 more2026-07-21
CVE-2026-60213 [MEDIUM] CWE-400 CVE-2026-60213: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result
nvd
CVE-2020-36518P3HIGHCVSS 7.5v14.1.1.0.02022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2026-60243P3MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60243 [MEDIUM] CWE-400 CVE-2026-60243: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability ca
nvd
CVE-2026-60245P3HIGHCVSS 7.2v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60245 [HIGH] CWE-284 CVE-2026-60245: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. Succes
nvd
CVE-2026-60304P3MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60304 [MEDIUM] CWE-284 CVE-2026-60304: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability ca
nvd