Impact
A flaw in the Messaging Enabler component of Oracle Service Delivery Platform permits an unauthenticated attacker who can reach the SOAP interface to gain full control of the application. By sending specially crafted SOAP messages, the attacker bypasses authentication, allowing complete compromise of confidentiality, integrity, and availability. The weakness is an authentication bypass, corresponding to CWE-306.
Affected Systems
Oracle Service Delivery Platform from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0. No other products are listed as impacted, but successful exploitation may also affect ancillary services integrated with the platform.
Risk and Exploitability
The CVSS v3.1 score of 10.0 indicates critical severity, while the EPSS score of less than 1% signals that exploitation attempts are expected to be rare. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve remote network access to the platform’s SOAP endpoint; an attacker does not need authentication to initiate the exploit. If successful, the attacker can take over the Service Delivery Platform, potentially affecting other integrated applications.
OpenCVE Enrichment