Impact
The vulnerability resides in the Platform component of Oracle Communications Billing and Revenue Management. It allows a low‑privileged user who can log into the infrastructure that hosts the product to gain full control over the application. Successful exploitation leads to a complete takeover, compromising confidentiality, integrity, and availability for the entire instance. The CVSS vector indicates a local attack with low attack complexity, low privileges, and no user interaction, yet the impact is high in all three security dimensions.
Affected Systems
Oracle Communications Billing and Revenue Management version 15.0.0.0.0 through 15.0.1.0.0 and 15.1.0.0.0 through 15.2.0.0.0 are affected.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. The EPSS score of less than 1% shows that the probability of exploitation at any given time is currently low, and the vulnerability is not yet listed in CISA’s KEV catalogue. Nevertheless, because the attack requires only local access and low privileges, the risk remains significant for systems that expose local logon capabilities to less trusted users. The analyzer infers that successful exploitation would allow a local attacker to bypass all controls and fully compromise the application.
OpenCVE Enrichment