Impact
This vulnerability resides in the Messaging Enabler component of Oracle’s Service Delivery Platform. An improper access control flaw permits a low‑privileged network user, able to reach the platform via the T3 or IIOP protocols, to execute privileged functions. Successful exploitation enables the attacker to create, delete or modify critical data, or obtain full read access to all Service Delivery Platform data, and can trigger a partial denial of service. The weakness results in confidentiality, integrity, and availability impacts, with a scope change that may affect other related Oracle Fusion Middleware products.
Affected Systems
Affected deployments are Oracle Corporation’s Service Delivery Platform within Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability targets the Messaging Enabler sub‑component and is reachable through network protocols T3 and IIOP.
Risk and Exploitability
The CVSS v3.1 score of 9.9 indicates a critical severity, reflecting remote network exploitation (AV:N), low attack complexity (AC:L), local privileges (PR:L), no user interaction (UI:N), and a scope change (S:C). The EPSS score of < 1% means current evidence of exploitation in the wild is very low but not zero. It is not listed in CISA’s KEV catalog, though the high severity and identified network attack surfaces suggest it is worthy of early attention. The likely attack vector is a low‑privileged attacker who can communicate with the platform over exposed T3 or IIOP interfaces.
OpenCVE Enrichment