Executive brief
A security vulnerability exists in the Messaging Enabler component of Oracle's Service Delivery Platform, a middleware suite used for managing telecommunications and enterprise services. An attacker who already has basic access to the server hosting this software can exploit this flaw to gain full control over the platform's data. This could lead to the unauthorized theft, modification, or deletion of sensitive business information and potentially impact other connected systems.
Technical details
This vulnerability affects the Messaging Enabler component within Oracle Fusion Middleware's Service Delivery Platform. It is classified as a local exploit, requiring the attacker to have an existing logon to the infrastructure where the platform executes. The flaw is characterized by a scope change (CVSS S:C), meaning a successful exploit can impact resources beyond the immediate security scope of the Service Delivery Platform. Attackers can achieve high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all platform-accessible data. The vulnerability is present in versions 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this advisory.
- 2026-07-21: disclosed