Impact
The vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, allowing an attacker who can reach the platform over the T3 or IIOP protocols, even with only low privileges, to acquire unauthorized access that can lead to complete takeover of the platform. The flaw is an instance of improper access control (CWE‑284) and would give the attacker control over confidential, integral, and available resources, effectively enabling remote code execution and full compromise of the affected service.
Affected Systems
Affected installations include Oracle Corporation's Service Delivery Platform in the Fusion Middleware suite. The issue impacts versions 12.2.1.4.0 and 14.1.2.0.0. No other products are directly referenced, but the description notes that successful exploitation may extend to other Oracle services through scope amplification.
Risk and Exploitability
The CVSS base score is 9.9, indicating catastrophic impact with confidentiality, integrity, and availability fully compromised. The EPSS score is below 1%, suggesting low current exploitation probability, and the vulnerability is not recorded in CISA's KEV catalog. However, because the attack requires network access to the T3 or IIOP ports and only low privileges, an attacker who can reach the affected host could exploit the flaw with high success probability in a suitable environment. The described scope change means that compromise of the Service Delivery Platform could extend to other Oracle services that run on the same host.
OpenCVE Enrichment