Impact
The Messaging Enabler component of Oracle Service Delivery Platform contains an unauthenticated network vulnerability. An attacker who can reach the T3 or IIOP ports can trigger the flaw without any prior credentials, giving the attacker full control over the platform. This results in complete loss of confidentiality, integrity, and availability. The associated CVSS vector shows a high severity with a base score of 9.8.
Affected Systems
The issue affects Oracle Corporation’s Service Delivery Platform product within Oracle Fusion Middleware. Supported releases that are vulnerable are 12.2.1.4.0 and 14.1.2.0.0. These versions are identified by the CPE strings provided.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and there is no record of exploitation in the CISA KEV catalog. Nevertheless, the vulnerability is easily exploitable via exposed T3 or IIOP network ports, and once accessed the attacker can attain system-wide compromise without authentication. This combination of high severity and low current exploitation probability still warrants swift remediation.
OpenCVE Enrichment