Impact
The vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform’s Fusion Middleware. It is an improper authorization flaw that allows an unauthenticated attacker with access to the platform’s T3 or IIOP interfaces to bypass authentication controls and gain full control of the platform. Successful exploitation results in complete compromise, giving the attacker the ability to execute arbitrary code, access sensitive data, and disrupt services.
Affected Systems
Oracle Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, is affected. All instances that deploy the Messaging Enabler component within these releases are vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 signals a critical threat. The EPSS score of less than 1% indicates a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated and can be reached over network protocols (T3 or IIOP), an attacker who can reach those ports on a hostile network may remotely take full control of the Service Delivery Platform, jeopardizing confidentiality, integrity, and availability.
OpenCVE Enrichment