CVE-2026-60235: High severity Oracle Oracle Coherence (Oracle Fusion Middleware) vulnerability
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data and unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Coherence (Oracle Fusion Middleware) - Coreto a version that resolves this vulnerability.Fixed in 15.1.1.0.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with network access to Oracle Coherence over TCP can exploit it. No privileges or user interaction are required.
Which deployments are known to be affected?
The affected supported Oracle Coherence version identified in the advisory is 15.1.1.0.0, in the Core component of Oracle Fusion Middleware.
What could a successful attack do?
A successful attack can cause Oracle Coherence to hang or crash repeatedly, resulting in complete denial of service. It can also allow unauthorized reading of a subset of accessible data and unauthorized insertion, modification, or deletion of some accessible data.