CVE-2023-21824

Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
References
Link Resource
https://www.oracle.com/security-alerts/cpujan2023.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.3.0:*:*:*:*:*:*:*

History

24 Jan 2023, 19:40

Type Values Removed Values Added
First Time Oracle communications Cloud Native Core Policy
Oracle communications Billing And Revenue Management Elastic Charging Engine
Oracle communications Cloud Native Core Binding Support Function
Oracle
CWE NVD-CWE-noinfo
References (MISC) https://www.oracle.com/security-alerts/cpujan2023.html - (MISC) https://www.oracle.com/security-alerts/cpujan2023.html - Patch, Vendor Advisory
CPE cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_billing_and_revenue_management_elastic_charging_engine:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.3.0:*:*:*:*:*:*:*

18 Jan 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-18 00:15

Updated : 2023-12-10 14:48


NVD link : CVE-2023-21824

Mitre link : CVE-2023-21824

CVE.ORG link : CVE-2023-21824


JSON object : View

Products Affected

oracle

  • communications_billing_and_revenue_management_elastic_charging_engine
  • communications_cloud_native_core_policy
  • communications_cloud_native_core_binding_support_function