Impact
Vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform. An unauthenticated attacker with network access via HTTP can trigger a crash by sending specially crafted requests. The flaw causes a complete hang or repeatable crash, reflected in a CVSS 3.1 Base Score of 7.5 that focuses on availability.
Affected Systems
Oracle Corporation’s Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, are impacted. No other versions are listed as affected in the current advisory.
Risk and Exploitability
The EPSS score is less than 1%, indicating that exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the lack of authentication requirements and the straightforward need for only HTTP access mean that an adversary could mount the attack over the network. The vulnerability’s high availability impact and ease of exploitation suggest that, if confronted, a successful attack would probably result in a complete denial of service for the affected platform.
OpenCVE Enrichment