CVE-2022-21424: High severity oracle communications billing and revenue management vulnerability
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-21424.
What is the affected software?
The affected software is Oracle Communications Billing and Revenue Management version 12.0.0.4.
What is the severity of CVE-2022-21424?
The severity of CVE-2022-21424 is high with a CVSS score of 8.3.
How can the vulnerability be exploited?
The vulnerability can be exploited by a low privileged attacker with network access via TCP.
Is there a fix available for CVE-2022-21424?
Please refer to the vendor's security advisory at https://www.oracle.com/security-alerts/cpuapr2022.html for information on available patches and fixes.