Vulnerability in Oracle Communications Billing and Revenue Management Product
CVE-2022-21422
7.5HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 April 2022
Summary
A network access vulnerability exists in the Oracle Communications Billing and Revenue Management product, specifically in the Connection Manager component. Supported versions 12.0.0.4 and 12.0.0.5 are at risk, potentially allowing low-privileged attackers with TCP network access to exploit this flaw. If successfully exploited, an attacker could take control of the Oracle Communications Billing and Revenue Management system, jeopardizing data confidentiality, integrity, and availability.
Affected Version(s)
Communications Billing and Revenue Management 12.0.0.4
Communications Billing and Revenue Management 12.0.0.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved