Executive brief
A vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, a middleware solution used for managing telecommunications and enterprise services. An attacker with low-level access to the network can exploit this to gain full control over sensitive data, potentially leading to data theft, unauthorized modifications, or service disruptions. Because this component interacts with other systems, an attack could also compromise additional connected business products.
Technical details
This vulnerability affects the Messaging Enabler component within Oracle Fusion Middleware's Service Delivery Platform. It is easily exploitable by a low-privileged attacker with network access using the T3 or IIOP protocols. The flaw is characterized by a 'scope change' (S:C), meaning a successful exploit can impact resources beyond the immediate security scope of the Service Delivery Platform. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as cause a partial denial of service. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory