Oracle Coherence vulnerabilities
115 known vulnerabilities affecting oracle/coherence.
Total CVEs
115
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL67HIGH30MEDIUM18
Vulnerabilities
Page 6 of 6
CVE-2026-60266P3MEDIUMCVSS 5.9v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60266 [MEDIUM] CWE-200 CVE-2026-60266: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2021-21409P3MEDIUMCVSS 5.9v12.2.1.4.0v14.1.1.0.02021-03-30
CVE-2021-21409 [MEDIUM] CWE-444 CVE-2021-21409: Netty is an open-source, asynchronous event-driven network application framework for rapid developme
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the requ
nvd
CVE-2021-43797P3MEDIUMCVSS 6.5v12.2.1.4.0v14.1.1.0.02021-12-09
CVE-2021-43797 [MEDIUM] CWE-444 CVE-2021-43797: Netty is an asynchronous event-driven network application framework for rapid development of maintai
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead
nvd
CVE-2026-60270P3MEDIUMCVSS 5.5v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60270 [MEDIUM] CWE-284 CVE-2026-60270: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60231P4MEDIUMCVSS 5.4v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60231 [MEDIUM] CWE-284 CVE-2026-60231: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability c
nvd
CVE-2026-60238P4MEDIUMCVSS 5.4v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60238 [MEDIUM] CWE-284 CVE-2026-60238: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Co
nvd
CVE-2026-60283P4MEDIUMCVSS 5.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60283 [MEDIUM] CWE-200 CVE-2026-60283: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60260P4MEDIUMCVSS 5.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60260 [MEDIUM] CWE-200 CVE-2026-60260: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability
nvd
CVE-2026-60237P4MEDIUMCVSS 5.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60237 [MEDIUM] CWE-200 CVE-2026-60237: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in
nvd
CVE-2020-2949P4MEDIUMCVSS 5.3v3.7.1.0v12.1.3.0.0+2 more2020-04-15
CVE-2020-2949 [MEDIUM] CVE-2020-2949: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, Cache
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this
nvd
CVE-2018-20301P4MEDIUM≥ 0, < 0.5.22022-02-10
CVE-2018-20301 [MEDIUM] CWE-20 Permissive parameters and privilege escalation
Permissive parameters and privilege escalation
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request.
ghsaosv
CVE-2026-60265P4MEDIUMCVSS 6.0v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60265 [MEDIUM] CWE-284 CVE-2026-60265: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence. While
nvd
CVE-2026-60307P4MEDIUMCVSS 4.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60307 [MEDIUM] CWE-200 CVE-2026-60307: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability c
nvd
CVE-2026-60303P4MEDIUMCVSS 4.3v12.2.1.4.0v14.1.1.0.0+2 more2026-07-21
CVE-2026-60303 [MEDIUM] CWE-400 CVE-2026-60303: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Suppor
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability c
nvd
CVE-2026-60233P4MEDIUMCVSS 4.3v15.1.1.0.02026-07-21
CVE-2026-60233 [MEDIUM] CWE-400 CVE-2026-60233: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The s
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
← Previous6 / 6