Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Service Delivery Platform’s Messaging Enabler allows an attacker without credentials to compromise the entire platform, potentially leading to a full takeover. The vulnerability impacts confidentiality, integrity and availability, enabling the attacker to execute arbitrary code and control the affected system. It is classified as a severe security issue with an overall high impact.

Affected Systems

Oracle Corporation’s Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw specifically relates to the Messaging Enabler component within the Oracle Fusion Middleware stack.

Risk and Exploitability

The severity is reflected in a CVSS 3.1 base score of 9.8, indicating critical danger. The EPSS score is below 1%, suggesting exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires network access over the T3 or IIOP protocols and does not require any authentication, making the exposure to externally reachable systems significant.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Service Delivery Platform 12.2.1.4.0 or 14.1.2.0.0 as soon as it is available.
  • If a patch cannot be applied immediately, restrict inbound traffic on the T3 and IIOP ports with firewalls or network segmentation to deny unauthenticated remote access.
  • Monitor system and application logs for abnormal Messaging Enabler activity and enable alerts for unauthorized access attempts, ensuring rapid response to potential exploitation.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Payload Execution via Messaging Enabler in Oracle Service Delivery Platform

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Service Delivery Platform via Messaging Enabler

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Service Delivery Platform via Messaging Enabler
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:51:56.185Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60385

cve-icon Vulnrichment

Updated: 2026-07-24T16:51:51.154Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function