Impact
A vulnerability in the Oracle Communications Converged Application Server, located in the Core component, can be exploited by an unauthenticated attacker with network access over TCP/IP. If successfully exploited, the attacker is likely to gain full control of the server, potentially exposing all sensitive data stored or processed by the application. This weakness is due to improper authorization handling and is classified under CWE‑269, CWE‑287, and CWE‑306.
Affected Systems
The affected products are Oracle Communications Converged Application Server versions 8.2 and 8.3. No other versions or product lines are listed as affected. Oracle Communications, as the vendor, has identified the issue in the 8.2 and 8.3 releases.
Risk and Exploitability
The CVSS 8.1 score reflects high severity, with impacts on confidentiality, integrity, and availability. Based on the description, the attack vector is inferred to be remote over TCP/IP, with no authentication required and no user interaction needed. The EPSS score of less than 1% indicates that exploitation attempts are expected to be rare, but the potential impact remains significant. The vulnerability is not listed in CISA's KEV catalog; however, due to its high impact and the ability for an unauthenticated attacker to reach the vulnerable component from the network, system owners should treat it as a notable risk.
OpenCVE Enrichment