Impact
The vulnerability resides in the Messaging Enabler component of Oracle Service Delivery Platform. An unauthenticated attacker can send a specially crafted SOAP request over the network to bypass authentication and gain full control of the platform, leading to compromise of confidentiality, integrity, and availability. The weakness is classified as authentication bypass (CWE-287) and missing authentication or authorization (CWE-306).
Affected Systems
Affected products are Oracle Service Delivery Platform (Fusion Middleware) versions 12.2.1.4.0 and 14.1.2.0.0.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates high impact. The EPSS score of less than 1% suggests the likelihood of exploitation at the moment is very low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based, specifically via SOAP over HTTP/HTTPS, and requires no prior authentication. If exploited, an attacker can achieve full takeover of the Service Delivery Platform.
OpenCVE Enrichment