Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
Published: 2026-08-18
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform permits an unauthenticated attacker with TCP network access to create, delete, or modify critical data or repeatedly crash the platform, causing integrity and availability loss. The CVSS 3.1 vector indicates high complexity, no privileges required, and no user interaction, underscoring the ease with which an external actor could exploit the flaw.

Affected Systems

Oracle Corporation’s Service Delivery Platform, part of Oracle Fusion Middleware, is affected in versions 14.1.2.0.0 and 12.2.1.4.0. Products that integrate with or rely on this platform may also be impacted due to the scope change.

Risk and Exploitability

With a CVSS base score of 8.7 the vulnerability is high severity. Although the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the lack of a patch and the requirement of only TCP network access mean that exposed instances remain at high risk. Attackers who can reach the platform over the network can exploit the flaw without authentication or special privileges, making remediation a priority.

Generated by OpenCVE AI on August 18, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑specified security patch for Oracle Service Delivery Platform versions 14.1.2.0.0 and 12.2.1.4.0.
  • Restrict inbound TCP access to the Service Delivery Platform by firewall or network segmentation to trusted IP ranges, reducing exposure to potential attackers.
  • Monitor platform logs for unexpected creation, deletion, or modification requests and set alerts for repeated crash events to detect exploitation attempts.

Generated by OpenCVE AI on August 18, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Denial of Service in Oracle Service Delivery Platform
Weaknesses CWE-284
CWE-749
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:15.490Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:45.500

Modified: 2026-08-18T21:16:45.500

Link: CVE-2026-60860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:45:16Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-749

    Exposed Dangerous Method or Function

  • CWE-862

    Missing Authorization