Impact
The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform. It allows an attacker who can log into the same infrastructure to gain unauthorized update, insert or delete access to certain platform data, as well as read restricted data. The weakness enables the attacker to influence confidentiality and integrity of Platform data and may allow further compromise of other products that run on or interact with the Service Delivery Platform.
Affected Systems
Affected product is Oracle Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware deployments.
Risk and Exploitability
The CVSS base score of 5.2 indicates moderate risk, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. A locally privileged attacker, after authenticating to the infrastructure, can exploit the weakness without additional user interaction. The attack is likely to occur via local network or shared infrastructure access, as inferred from the description that an attacker must have logon rights to the service host. Although the scope change may allow impact on other components, the necessity of local access and low privileges limits the overall exploitable surface. If successfully exploited, the attacker could modify or delete data and access sensitive information within the platform, potentially cascading into connected services.
OpenCVE Enrichment