Executive brief
Oracle Fusion Middleware's Service Delivery Platform, a component that handles messaging and middleware communication, contains a critical vulnerability that allows a low-privileged attacker with network access to gain complete control over the system. An attacker could exploit this flaw to compromise confidentiality, integrity, and availability of the platform and potentially impact other connected systems in the enterprise infrastructure.
Technical details
The vulnerability exists in the Messaging Enabler component of Oracle Fusion Middleware's Service Delivery Platform. A low-privileged attacker with network access to the service can exploit this flaw via T3 or IIOP protocols (common Oracle middleware communication protocols) to bypass security controls. The vulnerability allows an authenticated attacker to escalate privileges and achieve complete system compromise, including arbitrary code execution. The scope is marked as changed, indicating the attack can impact additional connected products and services beyond the directly vulnerable Service Delivery Platform component. Patches are expected to be available through Oracle's security advisory.
Affected products
- Oracle Fusion Middleware Service Delivery Platform 12.2.1.4.0 and 14.1.2.0.0
Timeline
- 2026-09-15: disclosed