Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Messaging Enabler component of Oracle Fusion Middleware Service Delivery Platform. It is a flaw in access control that allows an unauthenticated attacker who can reach the system over network protocols T3 or IIOP to compromise the platform, potentially gaining full control. The flaw can lead to total loss of confidentiality, integrity and availability of the entire Service Delivery Platform, effectively allowing a remote takeover.

Affected Systems

Vendor: Oracle Corporation. Product: Service Delivery Platform (Oracle Fusion Middleware). Affected releases are 12.2.1.4.0 and 14.1.2.0.0. Any installations that include the Messaging Enabler component of these releases are vulnerable.

Risk and Exploitability

The CVSS base score of 9.8 indicates a critical level of severity, while the EPSS metric of less than 1% indicates a currently low but non-zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers need only network connectivity and do not require authentication to exploit the flaw, which suggests that a remote attacker could execute arbitrary code on the platform, escalating privileges and fully controlling the application. The risk remains high until a patch is applied or mitigated.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the patch released in Oracle CPU July 2026 for Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict inbound access to the T3 and IIOP ports to trusted IP ranges and disable them on untrusted networks.
  • Apply network segmentation or firewall rules to block any unsolicited traffic to the Service Delivery Platform components.
  • Continuously monitor system logs and network traffic for suspicious authentication attempts or abnormal usage of T3/IIOP services.

Generated by OpenCVE AI on August 2, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Oracle Service Delivery Platform Messaging Enabler

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover in Oracle Service Delivery Platform
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover in Oracle Service Delivery Platform
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:49:59.938Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60387

cve-icon Vulnrichment

Updated: 2026-07-24T16:49:53.950Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function