Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Service Delivery Platform Messaging Enabler component contains an authorization flaw that allows a low‑privileged attacker with network access over HTTP to request data normally protected by the platform. The flaw is a type of insufficient authentication/authorization that also increases a confidentiality boundary (CWE‑200). When successfully exploited, the attacker can read key business information or, because the vulnerability involves a scope change, obtain unrestricted access to every datum the platform exposes. The impact is a loss of confidentiality for critical data or a complete compromise of platform‑accessible data.

Affected Systems

Affected are Oracle Service Delivery Platform version 12.2.1.4.0 and 14.1.2.0.0, specifically the Messaging Enabler plug‑in leveraged throughout the Oracle Fusion Middleware stack. No other SDP versions are mentioned.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 reflects a network attack (AV:N) that requires low privilege (PR:L) but does not require user interaction. A scope change (S:C) indicates that a compromised component can affect the overall confidentiality of the platform. The EPSS score of less than 1% and absence from CISA KEV suggest that, although the flaw is easy to use, it is currently unlikely to be widely exploited in the wild. Nevertheless, if the SDP instance is exposed to public or untrusted networks, the risk of a breach remains significant due to the potential to read all accessible data.

Generated by OpenCVE AI on August 4, 2026 at 17:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that resolves CVE‑2026‑60440 for Service Delivery Platform 12.2.1.4.0 or 14.1.2.0.0.
  • Limit HTTP/HTTPS access to the Messaging Enabler to trusted IP addresses or internal networks, configuring firewalls or ACLs to block all other traffic.
  • Enable detailed logging of Messaging Enabler HTTP requests and implement continuous monitoring to detect any unusual data retrieval attempts.

Generated by OpenCVE AI on August 4, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Allows Data Disclosure in Oracle Service Delivery Platform Messaging Enabler

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Allows Data Disclosure in Oracle Service Delivery Platform Messaging Enabler

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Unauthorized Data Access Vulnerability
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle Service Delivery Platform Unauthorized Data Access Vulnerability
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:17:04.011Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60440

cve-icon Vulnrichment

Updated: 2026-07-24T14:16:59.112Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor