Sceawere

Vulnerability Detail

CVE-2026-70790UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Telecommunications Billing Integrator Integrity Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Telecommunications Billing Integrator
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Telecommunications Billing Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Telecommunications Billing Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Telecommunications Billing Integrator accessible data. CVSS 3.1 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-08-18T21:17:32.673Z",
  "pubdate": "2026-08-18T21:17:32.673Z",
  "executiveSummary": "An unauthenticated, network-exploitable vulnerability affects the Oracle Telecommunications Billing Integrator component of Oracle E-Business Suite versions 12.2.3 through 12.2.15.\nThe vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the target system, resulting in unauthorized creation, deletion, or modification access to critical data or all accessible data within Oracle Telecommunications Billing Integrator.\nSuccessful exploitation requires human interaction from a user other than the attacker and introduces a scope change, meaning that attacks may significantly impact additional products beyond the immediately vulnerable component.\nWith a CVSS 3.1 Base Score of 7.4, the primary impact is concentrated on data integrity.\nThe combination of network vector accessibility, low attack complexity, lack of required authentication, and cross-product scope changes elevates the risk profile, making robust remediation essential for protecting enterprise data assets.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Telecommunications Billing Integrator, affecting supported product versions 12.2.3 to 12.2.15.\nNetwork exposure is enabled via the HTTP protocol, allowing remote adversaries without prior authentication or privileges to interact directly with the vulnerable service endpoints.\nThe attack flow requires human interaction, implying that an exploitation vector such as Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), or a related induced-action mechanism is likely leveraged to trick an authenticated or interacting user into executing unintended operations.\nUpon successful initiation of the attack vector, the malicious payload interacts with the Oracle Telecommunications Billing Integrator application logic.\nDue to insufficient input validation, authorization enforcement, or session handling within the vulnerable component, the application executes the requested operations without proper verification of the user's explicit intent.\nThe scope change (S:C) metric indicates that the vulnerability permits an attacker to transcend the security boundaries of the initial component, resulting in collateral impact and integrity compromise across additional integrated products within the ecosystem.\nThe post-exploitation impact is characterized by high integrity degradation (I:H), granting the attacker unauthorized capabilities to create, modify, or delete critical data structures or complete data sets accessible to the Oracle Telecommunications Billing Integrator product, while confidentiality and availability impacts remain unexpressed."
}
CVE-2026-70790: Oracle Telecommunications Billing Integrator Integrity Vulnerability (HIGH Severity, CVSS: 7.4) - Sceawere