Impact
A flaw in the Solution Designer component of Oracle Communications Service Catalog and Design allows a low‑privileged attacker with network access via HTTP to compromise the application. The vulnerability permits the attacker to take over the system, potentially impacting confidentiality, integrity, and availability. The weakness arises from insufficient permission checks, broken authorization, incorrect authentication handling, and missing access control.
Affected Systems
Oracle Communications Service Catalog and Design from Oracle Corporation; versions from 8.0.0.7.0 through 8.3.0.2.0 are vulnerable and may let this exploit succeed.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high‑severity risk. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, which may lower the immediate public exploitation likelihood. Nonetheless, the ability to compromise the system with low privilege over a network‑exposed HTTP endpoint and the potential for complete takeover suggests that a determined adversary could leverage this flaw if access is attainable.
OpenCVE Enrichment