Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-60389

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Ver en NVD

Análisis

Esta vulnerabilidad crítica en el componente Messaging Enabler de Oracle Fusion Middleware permite que un atacante no autenticado tome control total del Service Delivery Platform mediante peticiones HTTP. Debido a su calificación CVSS 10.0 y un cambio de alcance, el compromiso puede extenderse a otros servicios conectados en la infraestructura de la organización. Es imperativo actualizar las versiones afectadas para evitar una ejecución remota de código y la toma completa del servidor.

Roles relevantes

BackendJavaCloudCyberSecurity

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Publicada: 21/7/2026, 22:17:41
Última modificación: 21/7/2026, 22:17:41

Referencias

InicioEventosBlogRecursosEquipo