Impact
A flaw in Oracle Service Delivery Platform’s Messaging Enabler allows an attacker without credentials to compromise the entire platform, potentially leading to a full takeover. The vulnerability impacts confidentiality, integrity and availability, enabling the attacker to execute arbitrary code and control the affected system. It is classified as a severe security issue with an overall high impact.
Affected Systems
Oracle Corporation’s Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw specifically relates to the Messaging Enabler component within the Oracle Fusion Middleware stack.
Risk and Exploitability
The severity is reflected in a CVSS 3.1 base score of 9.8, indicating critical danger. The EPSS score is below 1%, suggesting exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires network access over the T3 or IIOP protocols and does not require any authentication, making the exposure to externally reachable systems significant.
OpenCVE Enrichment