Impact
The vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform permits an unauthenticated attacker with TCP network access to create, delete, or modify critical data or repeatedly crash the platform, causing integrity and availability loss. The CVSS 3.1 vector indicates high complexity, no privileges required, and no user interaction, underscoring the ease with which an external actor could exploit the flaw.
Affected Systems
Oracle Corporation’s Service Delivery Platform, part of Oracle Fusion Middleware, is affected in versions 14.1.2.0.0 and 12.2.1.4.0. Products that integrate with or rely on this platform may also be impacted due to the scope change.
Risk and Exploitability
With a CVSS base score of 8.7 the vulnerability is high severity. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the lack of a patch and the requirement of only TCP network access mean that exposed instances remain at high risk. Attackers who can reach the platform over the network can exploit the flaw without authentication or special privileges, making remediation a priority.
OpenCVE Enrichment