CVE-2021-2277: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are
highvulnerability
security
Summary
A vulnerability in Oracle Coherence (a data management tool used in Oracle Fusion Middleware) allows attackers on a network to access it without authentication over HTTP and read sensitive data. The vulnerability affects versions 3.7.1.0 through 14.1.1.0.0 and has a CVSS score (a 0-10 rating of how severe a vulnerability is) of 7.5, indicating it is serious.
Vulnerability Details
CVSS Score
7.5(high)
EPSS (30-day exploit probability)
EPSS: 2.2%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-2277
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%