Executive brief
A vulnerability exists in Oracle Coherence, a data grid solution used for high-speed data processing and storage. An attacker who already has high-level administrative access to the underlying server can exploit this flaw to gain unauthorized access to sensitive data managed by the application. This could lead to a significant breach of confidential information across multiple integrated systems.
Technical details
A vulnerability in the Core component of Oracle Coherence (Oracle Fusion Middleware) allows for unauthorized data access. The flaw is exploitable by a high-privileged attacker who has local logon access to the infrastructure where Oracle Coherence is running. While the vulnerability resides within Coherence, the 'scope change' (S:C) designation indicates that an exploit can impact other components or products beyond the immediate Coherence environment. Successful exploitation results in a complete loss of confidentiality for all data accessible to the Coherence service. Affected versions include 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published