CVE-2022-21422: High severity oracle communications billing and revenue management vulnerability
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21422?
CVE-2022-21422 is a vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications.
Which versions of Oracle Communications Billing and Revenue Management are affected by CVE-2022-21422?
The affected versions of Oracle Communications Billing and Revenue Management are 12.0.0.4 and 12.0.0.5.
What is the severity of CVE-2022-21422?
CVE-2022-21422 has a severity rating of 7.5 (High).
How can an attacker exploit CVE-2022-21422?
CVE-2022-21422 is a difficult to exploit vulnerability that requires network access and allows a low privileged attacker to execute certain actions.
Is there a patch available for CVE-2022-21422?
Yes, Oracle has released patches to address the vulnerability. Please refer to the Oracle Security Advisory for more information.