Impact
A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows an unauthenticated attacker with network access via HTTP to compromise the entire platform. The flaw enables full takeover, leading to loss of confidentiality, integrity, and availability. This represents a high‑severity remote code execution weakness, as reflected in the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Systems
Oracle Corporation’s Service Delivery Platform (Fusion Middleware) is impacted. Versions 12.2.1.4.0 and 14.1.2.0.0 are listed as affected. No other vendors or versions are mentioned in the advisories provided.
Risk and Exploitability
The CVSS score of 9.8 indicates critical risk, while the EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is very low. Nonetheless, the vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been confirmed in widespread exploitation, but the potential impact remains high. The attack vector is inferred to be remote over HTTP, with no authentication required, so any network‑connected host that can reach the Messaging Enabler endpoint could be targeted.
OpenCVE Enrichment