Vulnerabilities > Oracle > Coherence

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-25649 XXE vulnerability in multiple products
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly.
7.5
2020-07-15 CVE-2020-14642 Improper Resource Shutdown or Release vulnerability in Oracle Coherence
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: CacheStore).
network
low complexity
oracle CWE-404
7.5
2020-04-15 CVE-2020-2949 Unspecified vulnerability in Oracle Coherence
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation).
network
low complexity
oracle
5.3
2020-04-15 CVE-2020-2915 Unspecified vulnerability in Oracle Coherence
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching, CacheStore, Invocation).
network
low complexity
oracle
critical
9.8
2020-01-15 CVE-2020-2555 Deserialization of Untrusted Data vulnerability in Oracle products
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).
network
low complexity
oracle CWE-502
critical
9.8