Unauthorized Access Vulnerability in Oracle Communications Billing and Revenue Management
CVE-2022-21267

3.3LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability exists within the Oracle Communications Billing and Revenue Management product, specifically in the Pipeline Manager component. This weakness can be exploited by an attacker with low privileges who has logged onto the infrastructure where the application runs. By leveraging this vulnerability, attackers may gain unauthorized access to certain data within the application, potentially compromising sensitive information. The affected versions are 12.0.0.3 and 12.0.0.4. Organizations using these versions should consider implementing necessary security measures to mitigate exposure to this vulnerability.

Affected Version(s)

Communications Billing and Revenue Management 12.0.0.3

Communications Billing and Revenue Management 12.0.0.4

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.