Impact
A flaw in Oracle Service Delivery Platform’s Messaging Enabler component allows an attacker who can reach the network server over HTTP to perform unauthorized updates, inserts, deletions, and limited read operations on platform data without authentication. This results in potential compromise of data integrity and confidentiality for impacted datasets, with impact levels classified as low confidentiality and low integrity but no availability effect.
Affected Systems
Oracle Corporation’s Service Delivery Platform 14.1.2.0.0 is affected. The vulnerability arises in the Messaging Enabler component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based via HTTP, requiring no authentication and minimal effort to exploit. Successful exploitation enables an attacker to alter or read protected data on the platform, thereby compromising the platform’s integrity and confidentiality.
OpenCVE Enrichment