Impact
The Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform has a flaw that allows an unauthenticated attacker with HTTP network access to take full control of the platform, compromising confidentiality, integrity, and availability. The weakness originates from improper access control that enables remote code execution.
Affected Systems
Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases expose an HTTP endpoint that can be reached by anyone on the network, permitting the exploitation described.
Risk and Exploitability
The CVSS base score of 9.8 marks the vulnerability as critical. The EPSS score is below 1%, indicating a very low current exploitation probability, though the issue is not listed in CISA KEV. Attackers can reach the vulnerable endpoint over the network via HTTP without authentication; the exploit is described as easily exploitable and can result in full takeover of the platform.
OpenCVE Enrichment