Unauthenticated Access Vulnerability in Oracle Communications Billing Product
CVE-2022-21275
10CRITICAL
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 January 2022
Summary
A critical vulnerability exists in Oracle Communications Billing and Revenue Management, specifically in the Connection Manager component. This vulnerability allows an unauthenticated attacker with network access via HTTP to exploit the system. Successful exploitation can lead to a complete compromise of the billing system, potentially affecting additional services relying on it, hence posing significant risks to data confidentiality, integrity, and availability.
Affected Version(s)
Communications Billing and Revenue Management 12.0.0.3
Communications Billing and Revenue Management 12.0.0.4
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved