Impact
The Oracle Service Delivery Platform Messaging Enabler component contains an authorization flaw that allows a low‑privileged attacker with network access over HTTP to request data normally protected by the platform. The flaw is a type of insufficient authentication/authorization that also increases a confidentiality boundary (CWE‑200). When successfully exploited, the attacker can read key business information or, because the vulnerability involves a scope change, obtain unrestricted access to every datum the platform exposes. The impact is a loss of confidentiality for critical data or a complete compromise of platform‑accessible data.
Affected Systems
Affected are Oracle Service Delivery Platform version 12.2.1.4.0 and 14.1.2.0.0, specifically the Messaging Enabler plug‑in leveraged throughout the Oracle Fusion Middleware stack. No other SDP versions are mentioned.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 reflects a network attack (AV:N) that requires low privilege (PR:L) but does not require user interaction. A scope change (S:C) indicates that a compromised component can affect the overall confidentiality of the platform. The EPSS score of less than 1% and absence from CISA KEV suggest that, although the flaw is easy to use, it is currently unlikely to be widely exploited in the wild. Nevertheless, if the SDP instance is exposed to public or untrusted networks, the risk of a breach remains significant due to the potential to read all accessible data.
OpenCVE Enrichment