Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform permits an unauthenticated attacker with TCP network access to create, delete, or modify critical data or repeatedly crash the platform, causing integrity and availability loss. The CVSS 3.1 vector indicates high complexity, no privileges required, and no user interaction, underscoring the ease with which an external actor could exploit the flaw.

Affected Systems

Oracle Corporation’s Service Delivery Platform, part of Oracle Fusion Middleware, is affected in versions 14.1.2.0.0 and 12.2.1.4.0. Products that integrate with or rely on this platform may also be impacted due to the scope change.

Risk and Exploitability

With a CVSS base score of 8.7 the vulnerability is high severity. The EPSS score is below 1%, indicating a very low exploitation probability and, although the issue is not listed in the CISA KEV catalog, the requirement of only TCP network access means that exposed instances remain at high risk. Attackers who can reach the platform over the network can exploit the flaw without authentication or special privileges, making remediation a priority.

Generated by OpenCVE AI on August 21, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle for any available updates or patches for Service Delivery Platform 14.1.2.0.0 and 12.2.1.4.0, and apply promptly when released.
  • Restrict inbound TCP access to the Service Delivery Platform by firewall or network segmentation to trusted IP ranges, reducing exposure to potential attackers.
  • Monitor platform logs for unexpected creation, deletion, or modification requests and set alerts for repeated crash events to detect exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Denial of Service in Oracle Service Delivery Platform
Weaknesses CWE-749
CWE-862

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle fusion Middleware
CPEs cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:-:*:*:*:*:*:*:*
Vendors & Products Oracle fusion Middleware

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Denial of Service in Oracle Service Delivery Platform
Weaknesses CWE-284
CWE-749
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Service Delivery Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 8.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Fusion Middleware Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:03:38.540Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60860

cve-icon Vulnrichment

Updated: 2026-08-20T18:03:35.314Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:45.500

Modified: 2026-08-21T15:00:07.807

Link: CVE-2026-60860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:45:03Z

Weaknesses