Impact
A flaw in the Messaging Enabler component of Oracle Service Delivery Platform allows an unauthenticated attacker to gain full control of the platform using network access via the T3 and IIOP protocols. The vulnerability leads to an unrestricted compromise of confidentiality, integrity, and availability, effectively allowing attackers to take ownership of the Service Delivery Platform.
Affected Systems
The issue affects Oracle Corporation’s Service Delivery Platform product versions 12.2.1.4.0 and 14.1.2.0.0 within the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 underscores the severity of this remote vulnerability. The EPSS score of less than 1% indicates that exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog. However, the lack of authentication and the high impact suggest that once discovered a malicious actor could exploit this weakness to execute arbitrary code or otherwise take over the system.
OpenCVE Enrichment