Impact
The Oracle Service Delivery Platform's Messaging Enabler component contains an authentication bypass that allows an unauthenticated attacker to connect over the T3 or IIOP protocols. An attacker can send specially crafted requests that are processed without verifying credentials, leading to a full compromise of the platform. The flaw results in loss of confidentiality, integrity and availability, allowing an attacker to execute arbitrary code, extract data, or disable the service.
Affected Systems
Affect Oracle Corporation Service Delivery Platform for versions 12.2.1.4.0 and 14.1.2.0. These versions are part of Oracle Fusion Middleware and are commonly deployed in enterprise integration scenarios. The vulnerability resolves when the product is updated to a fixed release, as indicated in Oracle's security advisory.
Risk and Exploitability
CVSS 3.1 score of 9.8 indicates critical severity. The EPSS score is less than 1%, suggesting low current exploitation probability, and the vulnerability is not yet listed in CISA KEV. However, the flaw is easily exploitable over the network, with no user interaction or elevated privileges required. An attacker with TCP connectivity to the T3 or IIOP ports can trigger the bug and gain full control of the Service Delivery Platform.
OpenCVE Enrichment