Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Thu, 30 Jul 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Vulnerability Enabling Full Server Takeover in Oracle Communications Converged Application Server | |
| Weaknesses | CWE-284 CWE-306 |
Mon, 27 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Access Compromise in Oracle Communications Converged Application Server 8.x | |
| Weaknesses | CWE-284 CWE-287 |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Access Compromise in Oracle Communications Converged Application Server 8.x | |
| Weaknesses | CWE-284 CWE-287 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). Supported versions that are affected are 8.2 and 8.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Converged Application Server. While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle communications Converged Application Server |
|
| CPEs | cpe:2.3:a:oracle:communications_converged_application_server:8.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_converged_application_server:8.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle communications Converged Application Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:38:48.227Z
Updated: 2026-07-22T19:19:57.655Z
Reserved: 2026-07-08T15:52:20.741Z
Link: CVE-2026-61223
No data.
No data.
No data.