Impact
The vulnerability is an authentication bypass (CWE-306). An unauthenticated attacker with network access via HTTP can exploit the Messaging Enabler component in the Service Delivery Platform to gain complete control over the platform. This leads to exposure of all confidential data, compromise of user sessions, and disruption of service availability. The CVE explicitly states that successful attacks can result in takeover of the Service Delivery Platform.
Affected Systems
Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The Messaging Enabler component in these versions can be exploited.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates critical impact. EPSS score is less than 1%, suggesting limited current exploitation probability. The vulnerability is not listed in CISA KEV. Attack vector is network-based over HTTP, requiring no prior authentication. Even though exploitation may be uncommon, the potential for complete platform compromise warrants urgent attention.
OpenCVE Enrichment