Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Messaging Enabler component of Oracle Service Delivery Platform contains an unauthenticated network vulnerability. An attacker who can reach the T3 or IIOP ports can trigger the flaw without any prior credentials, giving the attacker full control over the platform. This results in complete loss of confidentiality, integrity, and availability. The associated CVSS vector shows a high severity with a base score of 9.8.

Affected Systems

The issue affects Oracle Corporation’s Service Delivery Platform product within Oracle Fusion Middleware. Supported releases that are vulnerable are 12.2.1.4.0 and 14.1.2.0.0. These versions are identified by the CPE strings provided.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and there is no record of exploitation in the CISA KEV catalog. Nevertheless, the vulnerability is easily exploitable via exposed T3 or IIOP network ports, and once accessed the attacker can attain system-wide compromise without authentication. This combination of high severity and low current exploitation probability still warrants swift remediation.

Generated by OpenCVE AI on August 4, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the Messaging Enabler missing‑authentication flaw (CWE‑306).
  • Disable unauthenticated access to the Messaging Enabler by configuring the T3 and IIOP endpoints to require authentication or restrict them to trusted IP ranges, thereby enforcing proper access control.
  • Implement network segmentation or firewall rules to block or limit inbound connections on the T3 and IIOP ports from untrusted sources.
  • Continuously monitor platform logs for signs of unauthorized activity and conduct regular security audits to verify that the authentication controls remain effective.

Generated by OpenCVE AI on August 4, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated network vulnerability in Oracle Service Delivery Platform Messaging Enabler allowing system takeover

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Service Delivery Platform Messaging Enabler
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:58:52.842Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60376

cve-icon Vulnrichment

Updated: 2026-07-24T16:58:05.839Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function