Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform. An unauthenticated attacker with network access via HTTP can trigger a crash by sending specially crafted requests. The flaw causes a complete hang or repeatable crash, reflected in a CVSS 3.1 Base Score of 7.5 that focuses on availability.

Affected Systems

Oracle Corporation’s Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, are impacted. No other versions are listed as affected in the current advisory.

Risk and Exploitability

The EPSS score is less than 1%, indicating that exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the lack of authentication requirements and the straightforward need for only HTTP access mean that an adversary could mount the attack over the network. The vulnerability’s high availability impact and ease of exploitation suggest that, if confronted, a successful attack would probably result in a complete denial of service for the affected platform.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Service Delivery Platform to a version that includes the patch referenced in the Oracle CPU July 2026 advisory.
  • If a patch is not immediately available, apply the recommended temporary mitigation from the same advisory, such as limiting HTTP access to trusted IP addresses or applying firewall rules to block suspicious traffic patterns.
  • Segregate Service Delivery Platform from untrusted networks and monitor for signs of abnormal traffic that could indicate an attempted exploitation.

Generated by OpenCVE AI on August 2, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Messaging Enabler Denial of Service via Unauthenticated HTTP

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Service Delivery Platform Denial of Service via Unauthenticated HTTP Exploit
Weaknesses CWE-389
CWE-770

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Service Delivery Platform Denial of Service via Unauthenticated HTTP Exploit
Weaknesses CWE-389
CWE-770

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:00:53.249Z

Reserved: 2026-07-08T15:51:40.533Z

Link: CVE-2026-60382

cve-icon Vulnrichment

Updated: 2026-07-24T14:00:38.064Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption