Impact
Vulnerability in the RTP Proxy component of Oracle Communications Converged Application Server 8.3 allows an attacker with high‑privileged local access to the host infrastructure to take full control of the application server. The flaw is a permission‑management weakness that permits escalation of privileges within the server process, leading to complete compromise of confidentiality, integrity, and availability. Successful exploitation results in a server takeover and can potentially affect other products shared by the same infrastructure because the vulnerability’s impact scope can change.
Affected Systems
Oracle Communications Converged Application Server 8.3, specifically the RTP Proxy component. The vulnerability may also impact additional components of the application server or other applications running on the same host if the scope changes during exploitation.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 signals a high severity for confidentiality, integrity, and availability. The EPSS score is below 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating that widespread exploitation has not been observed. The attack vector is inferred to be local, requiring an attacker who already has high‑privileged credentials on the host. Even though the opportunity for exploitation is limited, the resulting full control of the server makes this a high‑risk vulnerability if the conditions are met.
OpenCVE Enrichment