Unauthorized Access Vulnerability in Oracle Communications Billing and Revenue Management
CVE-2022-21431

10CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A vulnerability exists in Oracle's Billing and Revenue Management system that allows unauthenticated attackers with network access via TCP to compromise the application. This flaw can lead to unauthorized control over the system, potentially affecting the integrity, confidentiality, and availability of the data managed by the application. The vulnerability is present in versions 12.0.0.4 and 12.0.0.5, and attackers exploiting this flaw may also impact other interconnected systems, emphasizing the need for immediate attention and remediation measures.

Affected Version(s)

Communications Billing and Revenue Management 12.0.0.4

Communications Billing and Revenue Management 12.0.0.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.