Impact
The vulnerability resides in the Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform. It is a flaw in access control that allows an unauthenticated attacker who can reach the system over network protocols T3 or IIOP to compromise the platform, potentially gaining full control. The flaw can lead to total loss of confidentiality, integrity and availability of the entire Service Delivery Platform, effectively allowing a remote takeover.
Affected Systems
Vendor: Oracle Corporation. Product: Service Delivery Platform (Oracle Fusion Middleware). Affected releases are 12.2.1.4.0 and 14.1.2.0.0. Any installations that include the Messaging Enabler component of these releases are vulnerable.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical level of severity, while the EPSS metric of less than 1% indicates a currently low but non-zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers need only network connectivity and do not require authentication to exploit the flaw, which suggests that a remote attacker could execute arbitrary code on the platform, escalating privileges and fully controlling the application. The risk remains high until a patch is applied or mitigated.
OpenCVE Enrichment