Impact
A vulnerability in Oracle Service Delivery Platform permits a low‑privileged attacker with network access via Oracle Net to create, delete, or modify critical data, granting unauthorized and complete access to all data handled by the platform. The flaw, described as easily exploitable, can cause significant loss of confidentiality and integrity. The CVSS 3.1 base score of 9.6 reflects the severe impact on confidentiality and integrity, while availability is not affected.
Affected Systems
The affected products are Oracle Corporation Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0 running on Oracle Fusion Middleware. No other versions are listed as vulnerable.
Risk and Exploitability
The risk is high due to the high CVSS score and the possibility of a remote attack vector (network access). The exploitability is likely straightforward for an attacker possessing low privileges on the network, as the issue can be triggered by crafted messages sent over Oracle Net. This vulnerability also poses a scope change, potentially impacting additional Oracle products. While the EPSS score is < 1% and the vulnerability is not listed in CISA KEV, the severity and potential for wide‑reaching effects warrant immediate attention.
OpenCVE Enrichment