Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability originates in the Messaging Enabler component of Oracle’s Service Delivery Platform. It allows a local attacker who can log on to the host system to create, modify, or delete data managed by the platform, thereby compromising confidentiality and integrity. The flaw can also give the attacker access to all data exposed by the platform, possibly affecting other Oracle Fusion Middleware components that rely on Service Delivery Platform services.

Affected Systems

Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. Anyone running these versions on a host with local user access is at risk.

Risk and Exploitability

The CVSS 3.1 base score of 8.4 signals a high severity with substantial confidentiality and integrity impact. The EPSS score of less than 1% indicates that exploitation is rare at present. However, because the flaw changes scope, a successful local attack could elevate privileges and potentially affect additional Oracle Fusion Middleware products. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Patch released in the July 2026 update for Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict local account privileges on the servers running the platform, ensuring only necessary users can log on.
  • If the Messaging Enabler component is not needed for business processes, disable or remove it to reduce the attack surface.
  • Until a patch or official workaround is available, isolate the Service Delivery Platform from the rest of the network and monitor for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low-Privileged Local Access Enables Unauthorized Data Modification in Oracle Service Delivery Platform

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged Local Access Enables Unauthorized Data Modification in Oracle Service Delivery Platform

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Logon Exploitation Leading to Service Delivery Platform Compromise

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Logon Exploitation Leading to Service Delivery Platform Compromise
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data as well as unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:01:46.828Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60383

cve-icon Vulnrichment

Updated: 2026-07-24T14:01:42.460Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses