Impact
This vulnerability exists in the Internal Operations component of Oracle Telecommunications Billing Integrator. The flaw is a CWE‑284 improper authorization weakness that allows an attacker with low privileges who can reach the system over HTTP to create, delete, or modify critical data, giving full unauthorized access to all data exposed by the integrator. The flaw exposes confidentiality and integrity, enabling possible theft or alteration of billing information.
Affected Systems
Oracle Telecommunications Billing Integrator from Oracle Corporation. Affected releases are 12.2.3 through 12.2.15, accessed over HTTP within an internal network or from any host that can reach the component.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates a high‑severity flaw, while the EPSS score of less than 1% suggests that exploitation is currently very unlikely. The vulnerability is not included in the CISA KEV catalog. An attacker can exploit the flaw by sending crafted HTTP requests to the Internal Operations endpoint. The description indicates that only low‑privileged network access is required, so the attack can be carried out from any host that can reach the HTTP service.
OpenCVE Enrichment