Impact
The vulnerability allows a low‑privileged user who can log into the infrastructure where Oracle Communications Pricing Design Center runs to obtain unauthorized access to the application. By exploiting this flaw, the attacker can read critical data with high confidentiality impact and modify data with lower integrity impact, potentially disrupting pricing calculations or business operations. The weakness is a form of improper access control.
Affected Systems
Affected are the Oracle Communications Pricing Design Center releases 15.0.0.0.0 through 15.2.0.0.0. These versions include the On‑premise Deployment component that has not yet received a patch. An organization running any of these builds is susceptible to compromise as described. No other product versions are listed as affected.
Risk and Exploitability
The CVSS base score is 7.3, with local acquisition of privileges as the attack vector and low privilege required. The EPSS score is below 1 %, indicating that exploitation is unlikely in the current threat landscape, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw allows an attacker to read and modify sensitive data within the system, it warrants immediate attention, especially for deployments that process critical pricing information. The exploit requires only local access to the machine, suggesting that any log‑on credentials or compromised credentials present an opportunity for attack, and the scope may extend to additional products in the environment.
OpenCVE Enrichment