Executive brief
Oracle Coherence is a distributed data caching and processing platform used in enterprise applications to improve performance and availability. A vulnerability in the Core component allows an authenticated attacker to partially disrupt the service, reducing availability to legitimate users. This could impact business operations that depend on Coherence for real-time data processing and caching.
Technical details
This is a partial denial-of-service vulnerability in Oracle Coherence affecting the Core component. The vulnerability is easily exploitable and requires low-level privileges with network access via HTTP. No code execution or data confidentiality/integrity impacts are possible; only partial service availability is affected. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Patches or mitigations should be available through Oracle's standard security update process.
Affected products
- Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
Timeline
- 2026-09-15: disclosed