Impact
This vulnerability allows a low‑privileged user who has logged on to the underlying infrastructure to gain complete control over the Oracle Communications Billing and Revenue Management (BRM) Server. A successful exploitation results in the attacker taking over the BRM service, compromising confidentiality, integrity and availability of the charging and billing functions. The weakness resides in a local privilege escalation flaw that enables the attacker to bypass normal security controls and perform unauthorized operations.
Affected Systems
Oracle Communications Billing and Revenue Management servers running versions 15.0.0.0.0, 15.0.1.0.0, 15.1.0.0.0 and 15.2.0.0.0 are vulnerable. These versions are deployed by organizations using Oracle’s communications billing solution but the information does not specify if any later releases contain a fix.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.8 reflects significant impact to all three core security properties. With an AV:L vector the exploit requires local login but low effort and no user interaction, making it relatively easy to execute. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation today, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits full takeover of a critical billing system, it represents a high operational risk for any organization that can be compromised by a local attacker.
OpenCVE Enrichment