Impact
The vulnerability allows an attacker with low privileges who has logged on to the infrastructure where Oracle Communications BRM – Elastic Charging Engine runs to compromise the application. A successful exploit can lead to a full takeover, resulting in confidentiality, integrity, and availability losses for the entire system. This weakness corresponds to CWE-269: Least Privilege Violation.
Affected Systems
Oracle Communications BRM – Elastic Charging Engine versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0, and 15.2.0.0.0 are affected.
Risk and Exploitability
With a CVSS score of high severity. The EPSS score of less than 1% indicates that the vulnerability is not listed in the CISA KEV catalog. The attack vector is local: an attacker who has logged onto the infrastructure without any user interaction. Once exploited, the attacker can take over the application and potentially elevate privileges within the system.
OpenCVE Enrichment