CVE-2022-21570: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are
highvulnerability
security
Summary
Oracle Coherence, a data management product in Oracle Fusion Middleware, has a vulnerability (CVE-2022-21570) that allows attackers without authentication to crash the system through network protocols called T3 and IIOP. This affects versions 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0, with a severity rating of 7.5 out of 10 (CVSS score, a standard measure of how serious a vulnerability is).
Vulnerability Details
CVSS Score
7.5(high)
EPSS (30-day exploit probability)
EPSS: 1.0%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-21570
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%