CVE-2022-21420: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are
criticalvulnerability
security
Summary
Oracle Coherence (a data management tool in Oracle Fusion Middleware) has a critical vulnerability (CVE-2022-21420) that allows attackers without authentication to take over the system by exploiting the T3 protocol (a communication method used by Oracle products), affecting versions 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0. The vulnerability has a CVSS score (a 0-10 severity rating) of 9.8, meaning it is extremely serious and impacts confidentiality, integrity, and availability of the system.
Vulnerability Details
CVSS Score
9.8(critical)
EPSS (30-day exploit probability)
EPSS: 1.8%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-21420
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%