Impact
A vulnerability in the Oracle Service Delivery Platform’s Messaging Enabler component permits an attacker with network connectivity over T3 or IIOP to bypass authentication and take full control of the platform. The flaw is a missing authentication weakness that leads to complete compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle Service Delivery Platform (Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.0.0, specifically the Messaging Enabler component, are impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 reflects a severe threat with loss of all three core security properties. The EPSS score is less than 1 %, indicating that widespread exploitation is currently low, but the unauthenticated network access and lack of authentication make it a high‑risk vulnerability for exposed environments. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment