Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Service Delivery Platform's Messaging Enabler component contains an authentication bypass that allows an unauthenticated attacker to connect over the T3 or IIOP protocols. An attacker can send specially crafted requests that are processed without verifying credentials, leading to a full compromise of the platform. The flaw results in loss of confidentiality, integrity and availability, allowing an attacker to execute arbitrary code, extract data, or disable the service.

Affected Systems

Affect Oracle Corporation Service Delivery Platform for versions 12.2.1.4.0 and 14.1.2.0. These versions are part of Oracle Fusion Middleware and are commonly deployed in enterprise integration scenarios. The vulnerability resolves when the product is updated to a fixed release, as indicated in Oracle's security advisory.

Risk and Exploitability

CVSS 3.1 score of 9.8 indicates critical severity. The EPSS score is less than 1%, suggesting low current exploitation probability, and the vulnerability is not yet listed in CISA KEV. However, the flaw is easily exploitable over the network, with no user interaction or elevated privileges required. An attacker with TCP connectivity to the T3 or IIOP ports can trigger the bug and gain full control of the Service Delivery Platform.

Generated by OpenCVE AI on August 2, 2026 at 22:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's update to the latest Service Delivery Platform release that includes the fix for CVE-2026-60374.
  • Block external access to the T3 and IIOP ports for the Service Delivery Platform using firewall rules or network segmentation.
  • Monitor audit logs for anomalous T3/IIOP traffic and review authentication events for suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Messaging Enabler in Oracle Service Delivery Platform

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:03:39.382Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60374

cve-icon Vulnrichment

Updated: 2026-07-24T17:03:25.306Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function