Executive brief
Oracle Service Delivery Platform is a middleware component used to deliver business-critical messaging and integration services. An unauthenticated attacker on the network can exploit this vulnerability via SOAP to gain complete control of the platform, leading to potential data theft, service disruption, and system compromise.
Technical details
This vulnerability in the Messaging Enabler component of Oracle Service Delivery Platform allows unauthenticated remote code execution via SOAP protocol. The attack requires only network access with no authentication, user interaction, or complex configuration needed (CVSS vector indicates AV:N/AC:L/PR:N/UI:N). Successful exploitation results in complete takeover of the Service Delivery Platform, compromising confidentiality, integrity, and availability. Affected versions are 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Service Delivery Platform 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed