Executive brief
Oracle Service Delivery Platform, a component of Fusion Middleware used for managing communications services, contains a security vulnerability in its Messaging Enabler component. A user with existing low-level access to the underlying server can exploit this flaw to view, modify, or delete sensitive application data. This could lead to unauthorized data manipulation and potentially impact other integrated business systems.
Technical details
A vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform (Fusion Middleware) allows for unauthorized data access and modification. The flaw is locally exploitable, requiring the attacker to have an existing logon to the infrastructure where the platform executes. While the vulnerability resides within the Service Delivery Platform, the CVSS 'Scope Change' indicates that an exploit can impact other components or products beyond the immediate security scope of the platform. Successful exploitation grants a low-privileged attacker the ability to read, insert, update, or delete a subset of accessible data. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published