Impact
Oracle Service Delivery Platform’s Messaging Enabler component has a critical authentication bypass that allows an unauthenticated attacker with network connectivity to exploit the service over HTTP. The vulnerability can be used to fully compromise the Service Delivery Platform, resulting in complete confidentiality, integrity, and availability loss. The vulnerability is categorised as CWE-287 and CWE-306, reflecting weak authentication and insufficient privilege checks.
Affected Systems
The affected product is Oracle Service Delivery Platform (Fusion Middleware). Versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. These versions are used through the Messaging Enabler module for inter‑system messaging.
Risk and Exploitability
The CVSS v3.1 score of 9.8 classifies the flaw as critical, though the EPSS score of less than 1% suggests low current exploit activity. The flaw is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. Nonetheless, the attack vector is simple – send a crafted HTTP request to a publicly reachable Service Delivery Platform instance – and no client‑side interaction is required, making the risk high for any exposed systems.
OpenCVE Enrichment