Impact
This vulnerability originates in the Messaging Enabler component of Oracle’s Service Delivery Platform. It allows a local attacker who can log on to the host system to create, modify, or delete data managed by the platform, thereby compromising confidentiality and integrity. The flaw can also give the attacker access to all data exposed by the platform, possibly affecting other Oracle Fusion Middleware components that rely on Service Delivery Platform services.
Affected Systems
Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. Anyone running these versions on a host with local user access is at risk.
Risk and Exploitability
The CVSS 3.1 base score of 8.4 signals a high severity with substantial confidentiality and integrity impact. The EPSS score of less than 1% indicates that exploitation is rare at present. However, because the flaw changes scope, a successful local attack could elevate privileges and potentially affect additional Oracle Fusion Middleware products. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment