Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low privileged attacker with network access to the Oracle Service Delivery Platform via the T3 and IIOP protocols to compromise the messaging enabler component and ultimately take control of the entire platform. Successful exploitation results in full loss of confidentiality, integrity and availability for all data processed by the platform, and because the scope change can affect additional Oracle products, the impact can cascade beyond the immediate target.

Affected Systems

Oracle Corporation’s Service Delivery Platform, specifically versions 12.2.1.4.0 and 14.1.2.0.0 of the Fusion Middleware product suite. Attackers need only network connectivity to the T3/IIOP endpoints exposed by these installations.

Risk and Exploitability

The CVSS score of 9.9 reflects the high severity of this remote code execution. The EPSS score of < 1% indicates that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the high impact and the relatively simple attack path – requiring only low privileges and network access – make it a significant risk for environments that expose these protocols to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses the Messaging Enabler component and upgrade to a version newer than 12.2.1.4.0 and 14.1.2.0.0
  • Restrict network access to the T3 and IIOP ports to trusted hosts only, using firewalls or VPNs to isolate the Service Delivery Platform from the broader network
  • Configure or enforce authentication for the Messaging Enabler so that even low‑privileged users cannot initiate privileged operations without proper credentials

Generated by OpenCVE AI on August 4, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Service Delivery Platform Messaging Enabler via T3 and IIOP

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Service Delivery Platform Messaging Enabler via T3 and IIOP

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle Service Delivery Platform via T3/IIOP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle Service Delivery Platform via T3/IIOP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:00:10.227Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60381

cve-icon Vulnrichment

Updated: 2026-07-24T13:59:59.530Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses