Impact
This vulnerability allows a low privileged attacker with network access to the Oracle Service Delivery Platform via the T3 and IIOP protocols to compromise the messaging enabler component and ultimately take control of the entire platform. Successful exploitation results in full loss of confidentiality, integrity and availability for all data processed by the platform, and because the scope change can affect additional Oracle products, the impact can cascade beyond the immediate target.
Affected Systems
Oracle Corporation’s Service Delivery Platform, specifically versions 12.2.1.4.0 and 14.1.2.0.0 of the Fusion Middleware product suite. Attackers need only network connectivity to the T3/IIOP endpoints exposed by these installations.
Risk and Exploitability
The CVSS score of 9.9 reflects the high severity of this remote code execution. The EPSS score of < 1% indicates that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the high impact and the relatively simple attack path – requiring only low privileges and network access – make it a significant risk for environments that expose these protocols to untrusted networks.
OpenCVE Enrichment