Description
Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Prov IF component of the Oracle Communications Convergent Charging Controller permits a high‑privileged attacker who can reach the device over HTTP to gain control of the system. An attacker must interact with someone else before the exploitation succeeds; on success, the attacker can take over the controller, compromising confidentiality, integrity, and availability.

Affected Systems

The Oracle Communications Convergent Charging Controller product of Oracle Corporation is affected. Versions 15.0.0.0.0 and 15.2.0.0.0 are listed as vulnerable.

Risk and Exploitability

The CVSS v3.1 base score of 6.4 highlights moderate to high risk. The attack vector is network (AV:N). Attack complexity is high (AC:H) and the required privileges are high (PR:H). User interaction is required (UI:R). The EPSS score is reported as less than 1 %, indicating a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would begin with an HTTP request to the Prov IF interface and requires a third‑party user’s interaction. While publicly available exploits are not known, the potential for full system takeover means vigilance is warranted.

Generated by OpenCVE AI on August 4, 2026 at 01:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch or update released for the Oracle Communications Convergent Charging Controller versions 15.0.0.0.0 and 15.2.0.0.0 that addresses this vulnerability.
  • Restrict network access to the controller's HTTP interface by configuring firewalls or network segmentation to limit connections to trusted hosts only.
  • Limit exposure by enforcing minimum necessary access control on the Prov IF interface, ensuring that only authenticated and authorized users can invoke privileged functions.
  • Review Oracle’s security advisory at https://www.oracle.com/security-alerts/cpujul2026.html for further guidance and confirm the patch status.

Generated by OpenCVE AI on August 4, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title High-Privilege Vulnerability Allowing Full Takeover of Oracle Communications Convergent Charging Controller

Thu, 30 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Vulnerability Allowing Full Takeover of Oracle Communications Convergent Charging Controller

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-304
CWE-601
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle communications Convergent Charging Controller
CPEs cpe:2.3:a:oracle:communications_convergent_charging_controller:15.0.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_convergent_charging_controller:15.2.0.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle communications Convergent Charging Controller
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Communications Convergent Charging Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T18:43:22.489Z

Reserved: 2026-07-08T15:52:20.736Z

Link: CVE-2026-61143

cve-icon Vulnrichment

Updated: 2026-07-23T18:43:18.580Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:45.640

Modified: 2026-07-23T19:16:58.143

Link: CVE-2026-61143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-304

    Missing Critical Step in Authentication

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password