Impact
The vulnerability is an access‑control flaw in the Messaging Enabler component that, based on the description, likely allows a low‑privileged attacker with network access via HTTP to send specially crafted requests that bypass authentication and gain privileged operations. The attacker can then configure the platform, extract data, and ultimately take full control, resulting in a loss of confidentiality, integrity and availability for the Service Delivery Platform and any dependent services.
Affected Systems
The flaw affects Oracle Service Delivery Platform versions 12.2.1.4.0 and 14.1.2.0.0. Because the vulnerability has a scope change, an attacker may also impact other Oracle Fusion Middleware components that run within the same environment, but the primary risk is the Service Delivery Platform itself.
Risk and Exploitability
The CVSS v3.1 base score of 9.9 indicates critical severity. The EPSS score of <1% suggests that the probability of exploitation is currently low, but the high‑impact nature of a platform takeover and the availability of the flaw with only basic network reachability make it a high‑priority exposure for any organization running the affected services. The vulnerability is not listed in the CISA KEV catalog, yet its exploitability via a simple HTTP request and the lack of technical prerequisites make it a significant risk.
OpenCVE Enrichment