Impact
An access‑control flaw in the Messaging Enabler component of Oracle Service Delivery Platform permits a low‑privileged attacker with network access to compromise the entire platform. The vulnerability is exploitation of improper authorization checks (CWE‑284) that can lead to full takeover, exposing all data and functions the platform manages. The flaw is easily exploitable once the attacker reaches the relevant services, and it delivers full control of confidentiality, integrity and availability.
Affected Systems
Affected systems include Oracle Service Delivery Platform releases 12.2.1.4.0 and 14.1.2.0. These versions are distributed as part of Oracle Fusion Middleware and are available to organizations running the platform on their infrastructure. The issue resides in the core messaging infrastructure and may impact other integrated Oracle Fusion products that share the same access control logic.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates critical impact. The EPSS score is reported as below 1 publicly. It is not listed in the CISA KEV catalog, but the attack vector is network‑based via T3 or IIOP protocols, and the attacker only requires low privileges to succeed. The compromise can spread beyond the initial host due to the scope change, potentially affecting additional connected services.
OpenCVE Enrichment