Impact
The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform, allowing an unauthenticated attacker with network reach to the system over T3 or IIOP to send malicious messages that are executed with the platform’s privileges. Successful exploitation leads to full takeover of the Service Delivery Platform, compromising confidentiality, integrity and availability of the system and its underlying data.
Affected Systems
Oracle’s Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected, with the Messaging Enabler component being the specific point of vulnerability.
Risk and Exploitability
The flaw carries a CVSS v3.1 base score of 9.8, classifying it as critical. The EPSS score of less than 1% indicates a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network access to the T3 and IIOP services, no authentication or user interaction is required, thereby giving them the potential to commandeer the entire platform.
OpenCVE Enrichment