Executive brief
Oracle Service Delivery Platform, a component of Oracle Fusion Middleware used for managing communication services, contains a critical security vulnerability in its Messaging Enabler component. An attacker can exploit this flaw over a network without any valid user credentials or interaction. A successful attack could lead to a complete takeover of the platform, potentially compromising sensitive communication data and disrupting business operations.
Technical details
A critical vulnerability exists in the Messaging Enabler component of Oracle Service Delivery Platform (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation allows for a complete takeover of the Service Delivery Platform, impacting confidentiality, integrity, and availability. The vulnerability is rated with a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory