Impact
The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform. An attacker with network access can send an unauthenticated HTTP request that permits compromise and a complete takeover of the platform. The flaw grants full confidentiality, integrity, and availability loss, and the vulnerability scope changes may allow additional Fusion Middleware products to be impacted.
Affected Systems
Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The affected software can be identified by the provided cpe strings. Because the vulnerability changes scope, ancillary Fusion Middleware products may also be impacted.
Risk and Exploitability
The CVSS score of 10.0 signals critical severity. The EPSS score of <1% indicates a low probability of current exploitation, but the attack vector is network‑based via HTTP and requires no credentials, making it easily reachable from the Internet. The flaw offers complete platform takeover; therefore, it warrants immediate attention even though it is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment