Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Messaging Enabler component of Oracle’s Service Delivery Platform. An improper access control flaw permits a low‑privileged network user, able to reach the platform via the T3 or IIOP protocols, to execute privileged functions. Successful exploitation enables the attacker to create, delete or modify critical data, or obtain full read access to all Service Delivery Platform data, and can trigger a partial denial of service. The weakness results in confidentiality, integrity, and availability impacts, with a scope change that may affect other related Oracle Fusion Middleware products.

Affected Systems

Affected deployments are Oracle Corporation’s Service Delivery Platform within Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability targets the Messaging Enabler sub‑component and is reachable through network protocols T3 and IIOP.

Risk and Exploitability

The CVSS v3.1 score of 9.9 indicates a critical severity, reflecting remote network exploitation (AV:N), low attack complexity (AC:L), local privileges (PR:L), no user interaction (UI:N), and a scope change (S:C). The EPSS score of < 1% means current evidence of exploitation in the wild is very low but not zero. It is not listed in CISA’s KEV catalog, though the high severity and identified network attack surfaces suggest it is worthy of early attention. The likely attack vector is a low‑privileged attacker who can communicate with the platform over exposed T3 or IIOP interfaces.

Generated by OpenCVE AI on August 4, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch or upgrade Service Delivery Platform to a non‑vulnerable release as provided by Oracle Support
  • Block or restrict inbound T3 and IIOP traffic to the platform using firewall or ACL rules so that only trusted hosts can reach these ports
  • Review and harden role‑based access controls on the platform, ensuring that only authorized users have rights to modify or delete data
  • Enable comprehensive audit logging for all privileged actions on the platform to help detect unauthorized activity

Generated by OpenCVE AI on August 4, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Messaging Enabler Access Control Flaw Enabling Unauthorized Data Modification

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Messaging Enabler Access Control Flaw Enabling Unauthorized Data Modification

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Messaging Enabler in Oracle Service Delivery Platform
Weaknesses CWE-285
CWE-862

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Messaging Enabler in Oracle Service Delivery Platform
Weaknesses CWE-284
CWE-285
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:57:12.826Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60377

cve-icon Vulnrichment

Updated: 2026-07-24T16:56:46.099Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses