OSA-37034620
Vulnerability in the Oracle Communications Converged Charging System product of Oracle Communications Applications (component: Security (Kerberos)). Supported versions that are affected are 2.0.0.0.0-2.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Charging System. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Converged Charging System accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Converged Charging System. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Risk Scores
Timeline
- Oct 20, 2025 CVE Published