Description
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows a high‑privileged attacker who can reach the platform over HTTP to compromise the service. The flaw arises from improper access control, enabling the attacker to read or modify critical data and potentially gain complete access to all data exposed by the platform. The CVSS vector shows a network attack, low complexity, high privileges required, no user interaction, and a scope change, resulting in a 6.8 base score that highlights confidentiality impact.

Affected Systems

The affected vendor is Oracle Corporation’s Service Delivery Platform. Versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. The problem occurs in the Messaging Enabler component of these releases.

Risk and Exploitability

The CVSS 3.1 base score of 6.8 indicates a moderate severity vulnerability. The EPSS score of < 1% suggests a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, indicating no known exploits. Nonetheless, the vulnerability can be exploited over HTTP without user interaction and requires only high‑privileged access, which may be attainable on compromised or poorly secured installations. The scope change indicates that the compromise could affect other Oracle products that rely on the Service Delivery Platform.

Generated by OpenCVE AI on August 21, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Service Delivery Platform patch or update as described in the Oracle security advisory to address the improper access control (CWE-284).
  • Restrict HTTP access so that only trusted IP addresses can reach the Service Delivery Platform
  • Disable or remove the Messaging Enabler component if it is not required for operational needs

Generated by OpenCVE AI on August 21, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title High-Privileged Access via Improper Access Control in Oracle Service Delivery Platform

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle fusion Middleware
CPEs cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:-:*:*:*:*:*:*:*
Vendors & Products Oracle fusion Middleware

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Service Delivery Platform via HTTP
Weaknesses CWE-732

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Service Delivery Platform via HTTP
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Service Delivery Platform accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle service Delivery Platform
CPEs cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Delivery Platform
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Fusion Middleware Service Delivery Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:24:12.858Z

Reserved: 2026-07-08T15:51:55.597Z

Link: CVE-2026-60865

cve-icon Vulnrichment

Updated: 2026-08-20T18:21:27.053Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:45.817

Modified: 2026-08-21T14:57:29.947

Link: CVE-2026-60865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:45:03Z

Weaknesses