Description
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center. While the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a low‑privileged user who can log into the infrastructure where Oracle Communications Pricing Design Center runs to obtain unauthorized access to the application. By exploiting this flaw, the attacker can read critical data with high confidentiality impact and modify data with lower integrity impact, potentially disrupting pricing calculations or business operations. The weakness is a form of improper access control.

Affected Systems

Affected are the Oracle Communications Pricing Design Center releases 15.0.0.0.0 through 15.2.0.0.0. These versions include the On‑premise Deployment component that has not yet received a patch. An organization running any of these builds is susceptible to compromise as described. No other product versions are listed as affected.

Risk and Exploitability

The CVSS base score is 7.3, with local acquisition of privileges as the attack vector and low privilege required. The EPSS score is below 1 %, indicating that exploitation is unlikely in the current threat landscape, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw allows an attacker to read and modify sensitive data within the system, it warrants immediate attention, especially for deployments that process critical pricing information. The exploit requires only local access to the machine, suggesting that any log‑on credentials or compromised credentials present an opportunity for attack, and the scope may extend to additional products in the environment.

Generated by OpenCVE AI on August 3, 2026 at 00:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade Oracle Communications Pricing Design Center to a version that addresses the vulnerability.
  • Restrict permissions for low‑privileged accounts on the infrastructure to enforce least privilege and minimize the attack surface.
  • Monitor system logs and network activity for signs of unauthorized data exfiltration or modification.

Generated by OpenCVE AI on August 3, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Communications Pricing Design Center permits unauthorized read and write of pricing data

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Exploit in Oracle Communications Pricing Design Center

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access Exploit in Oracle Communications Pricing Design Center

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center. While the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Pricing Design Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle communications Pricing Design Center
CPEs cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_pricing_design_center:15.0.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_pricing_design_center:15.1.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_pricing_design_center:15.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Pricing Design Center
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Communications Pricing Design Center
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:05:18.931Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47007

cve-icon Vulnrichment

Updated: 2026-07-23T15:05:13.334Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses