Impact
The anomaly originates in the Security component of Oracle Communications Converged Application Server versions 8.2 and 8.3. An unauthenticated attacker who can reach the server over the network can compromise the server. The vulnerability allows full takeover, compromising confidentiality, integrity and availability for the application and potentially for other products if the scope changes.
Affected Systems
Oracle Communications Converged Application Server 8.2 and 8.3 are affected. The advisory notes that if the vulnerability's scope changes, it may also impact other products in the environment.
Risk and Exploitability
The CVSS 3.1 base score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) classifies this as a critical issue. Exploitation requires only network access and is difficult, and the EPSS score of less than 1% indicates a low probability that the vulnerability is currently being targeted. Although it is not included in the CISA KEV catalog, the potential for total server takeover makes it a high‑risk concern.
OpenCVE Enrichment