Impact
The vulnerability in the Prov IF component of the Oracle Communications Convergent Charging Controller permits a high‑privileged attacker who can reach the device over HTTP to gain control of the system. An attacker must interact with someone else before the exploitation succeeds; on success, the attacker can take over the controller, compromising confidentiality, integrity, and availability.
Affected Systems
The Oracle Communications Convergent Charging Controller product of Oracle Corporation is affected. Versions 15.0.0.0.0 and 15.2.0.0.0 are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 6.4 highlights moderate to high risk. The attack vector is network (AV:N). Attack complexity is high (AC:H) and the required privileges are high (PR:H). User interaction is required (UI:R). The EPSS score is reported as less than 1 %, indicating a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation would begin with an HTTP request to the Prov IF interface and requires a third‑party user’s interaction. While publicly available exploits are not known, the potential for full system takeover means vigilance is warranted.
OpenCVE Enrichment