Impact
A flaw in Oracle Telecommunications Billing Integrator’s Internal Operations component allows an unauthenticated attacker who can reach the system over HTTP to create, delete, or alter critical data. The vulnerability is accessed via specially crafted HTTP requests and relies on improper access control to bypass authentication checks, enabling integrity violations across all data exposed by the product.
Affected Systems
Oracle Telecommunications Billing Integrator by Oracle Corporation, versions 12.2.3 through 12.2.15. The scope change flag indicates that compromised conditions may affect other Oracle products that interface with the billing integrator. No other vendors or products are presently listed.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 reflects a high integrity impact with low attack complexity and no required privileges, though the attack requires user interaction, which reduces the immediate exploitability. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation. Nevertheless, the remote HTTP access and the potential to influence multiple Oracle systems result in a moderate-to-high risk, especially in environments where the product is exposed to external traffic.
OpenCVE Enrichment