Executive brief
Oracle Coherence is a distributed caching and data grid product used to accelerate application performance. A vulnerability in its core component allows a local user with low-level access to read sensitive data that they shouldn't be able to access, potentially exposing cached information used by enterprise applications.
Technical details
The vulnerability is an information disclosure flaw in the Oracle Coherence Core component affecting version 15.1.1.0.0. It requires local access (adjacent/local attack vector) and low privileges with valid logon credentials, plus non-standard conditions (high complexity), making it difficult to exploit in practice. Successful exploitation enables unauthorized read access to a subset of Oracle Coherence accessible data. The CVSS 3.1 score is 2.5 (low severity) reflecting confidentiality impact only, with no integrity or availability effects. Patch status and mitigation guidance are available through Oracle's standard security advisory channels.
Affected products
- Oracle Coherence 15.1.1.0.0
Timeline
- 2026-09-15: disclosed