Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Service Delivery Platform accessible data as well as unauthorized read access to a subset of Service Delivery Platform accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform. It allows an attacker who can log into the same infrastructure to gain unauthorized update, insert or delete access to certain platform data, as well as read restricted data. The weakness enables the attacker to influence confidentiality and integrity of Platform data and may allow further compromise of other products that run on or interact with the Service Delivery Platform.

Affected Systems

Affected product is Oracle Service Delivery Platform, versions 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware deployments.

Risk and Exploitability

The CVSS base score of 5.2 indicates moderate risk, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. A locally privileged attacker, after authenticating to the infrastructure, can exploit the weakness without additional user interaction. The attack is likely to occur via local network or shared infrastructure access, as inferred from the description that an attacker must have logon rights to the service host. Although the scope change may allow impact on other components, the necessity of local access and low privileges limits the overall exploitable surface. If successfully exploited, the attacker could modify or delete data and access sensitive information within the platform, potentially cascading into connected services.

Generated by OpenCVE AI on August 4, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a version that contains the fix for this vulnerability
  • Restrict local logon rights and enforce least privilege on servers running Service Delivery Platform
  • Monitor platform logs for anomalous write or read activity to detect potential exploitation

Generated by OpenCVE AI on August 4, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Access Enables Unauthorized Data Modification and Read in Oracle Service Delivery Platform
Weaknesses CWE-110
CWE-532

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Logon Attack Enables Unauthorized Data Access and Modification in Oracle Service Delivery Platform
Weaknesses CWE-269
CWE-284

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Logon Attack Enables Unauthorized Data Access and Modification in Oracle Service Delivery Platform
Weaknesses CWE-269
CWE-284

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Control of Oracle Service Delivery Platform via Messaging Enabler Exploit
Weaknesses CWE-284
CWE-732

Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Control of Oracle Service Delivery Platform via Messaging Enabler Exploit
Weaknesses CWE-284
CWE-732

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Service Delivery Platform executes to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Service Delivery Platform accessible data as well as unauthorized read access to a subset of Service Delivery Platform accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:41:57.809Z

Reserved: 2026-07-08T15:51:40.541Z

Link: CVE-2026-60501

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-110

    Struts: Validator Without Form Field

  • CWE-532

    Insertion of Sensitive Information into Log File