Impact
A flaw in the Messaging Enabler component of Oracle Service Delivery Platform, identified as an authentication weakness (CWE-306), allows an unauthenticated attacker with network access to the T3 or IIOP protocols to compromise the platform. Successful exploitation can result in a full takeover, giving the attacker control over confidentiality, integrity, and availability of the affected system. The CVSS score of 9.8 reflects the severe impact across all three security dimensions.
Affected Systems
Oracle Corporation’s Service Delivery Platform is impacted, specifically the Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0. These releases are listed as affected by the CVE advisory.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is considered critical. The EPSS score of less than 1% indicates a low probability that exploitation is occurring in the wild, and the vulnerability is not yet included in CISA’s KEV catalog. The attack requires only network connectivity to the vulnerable ports and no credentials, so any host exposed to the T3 or IIOP traffic presents a potential vector for immediate compromise.
OpenCVE Enrichment