Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform, allowing an unauthenticated attacker with network reach to the system over T3 or IIOP to send malicious messages that are executed with the platform’s privileges. Successful exploitation leads to full takeover of the Service Delivery Platform, compromising confidentiality, integrity and availability of the system and its underlying data.

Affected Systems

Oracle’s Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected, with the Messaging Enabler component being the specific point of vulnerability.

Risk and Exploitability

The flaw carries a CVSS v3.1 base score of 9.8, classifying it as critical. The EPSS score of less than 1% indicates a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network access to the T3 and IIOP services, no authentication or user interaction is required, thereby giving them the potential to commandeer the entire platform.

Generated by OpenCVE AI on August 5, 2026 at 02:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Service Delivery Platform that addresses this issue
  • Restrict inbound traffic to the T3 and IIOP ports by configuring firewall rules to allow only trusted hosts
  • If the Messaging Enabler component is not essential, disable or remove it, or otherwise isolate the Service Delivery Platform from untrusted networks

Generated by OpenCVE AI on August 5, 2026 at 02:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Messaging Enabler in Oracle Service Delivery Platform

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Messaging Enabler Remote Code Execution
Weaknesses CWE-284
CWE-94

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Messaging Enabler Remote Code Execution
Weaknesses CWE-284
CWE-94

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Control via T3 and IIOP in Oracle Service Delivery Platform
Weaknesses CWE-270
CWE-284
CWE-306

Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Control via T3 and IIOP in Oracle Service Delivery Platform
Weaknesses CWE-270
CWE-284
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Service Delivery Platform. Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:46:34.292Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60388

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses

No weakness.