Impact
Oracle Communications Converged Application Server 8.3 contains a flaw in its Security component that permits a highly privileged attacker with network access over TLS to gain full control of the server. The weakness allows the attacker to compromise confidentiality, integrity, and availability, effectively resulting in a complete takeover. This access control failure is identified as CWE‑284.
Affected Systems
The affected product is Oracle Communications Converged Application Server version 8.3. No other Oracle product versions are listed as affected, but the CVE notes that the vulnerability may impact additional products due to a scope change.
Risk and Exploitability
The CVSS base score of 8.0 indicates high severity, while the EPSS score of less than 1 % suggests a low but nonzero likelihood of exploitation in the field. The vulnerability is not present in the CISA KEV catalog. The exploit is performed over a network connection using TLS, requiring a remote attacker to send crafted TLS traffic; no local compromise is necessary.
OpenCVE Enrichment