Known vulnerabilities in Oracle Communications Billing and Revenue Management

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_billing_and_revenue_management:*:*:*:*:*:*:*:*
Total vulnerabilities: 61
Public exploits: 6
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Billing and Revenue Management Oracle Communications Billing and Revenue Management is affected by 61 known vulnerabilities: 21 high, 28 medium, 12 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121709 - Improper input validation
CVE-2025-26333
CWE-20 Medium
No
No
- 20.01.2026 SB20260120100
SB20260120113
SB20260120120
and 7 more
#VU120231 - Improper Validation of Certificate with Host Mismatch
CVE-2025-68161
CWE-297 Medium
No
No
- 22.12.2025 SB2025122245
SB2026012084
SB2026012087
and 101 more
#VU114026 - Resource exhaustion
CVE-2025-55163
CWE-400 Medium
No
No
- 13.08.2025 SB2025081378
SB2025081948
SB2025081949
and 71 more
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Available
No
- 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU107411 - Heap-based Buffer Overflow
CVE-2024-56406
CWE-122 High
Available
No
- 14.04.2025 SB2025041424
SB2025041425
SB2025041429
and 18 more
#VU103770 - Improper input validation
CVE-2025-24970
CWE-20 Medium
No
No
- 11.02.2025 SB2025021186
SB202502197190
SB2025030409
and 88 more
#VU101829 - Improper Authentication
CVE-2024-56128
CWE-287 Medium
No
No
- 18.12.2024 SB2024121826
SB2025041647
SB2025041651
and 12 more
#VU101111 - Divide By Zero
CVE-2024-53122
CWE-369 Low
No
No
- 03.12.2024 SB2024120317
SB2025010804
SB2025010805
and 65 more
#VU98025 - Resource exhaustion
CVE-2024-47554
CWE-400 Medium
No
No
- 03.10.2024 SB2024100352
SB2024100421
SB2024101007
and 132 more
#VU93519 - Out-of-bounds read
CVE-2024-37371
CWE-125 Medium
No
No
12.0.0.8.0 01.07.2024 SB2024070148
SB2024070491
SB2024070496
and 114 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
12.0.0.8.0 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU90156 - Security Features
CVE-2024-35195
CWE-254 Low
No
No
- 31.05.2024 SB2024053174
SB2024053188
SB2024053192
and 117 more
#VU88576 - Improper input validation
CVE-2022-34381
CWE-20 High
No
No
- 16.04.2024 SB2024041703
SB2024041722
SB2024041723
and 7 more
#VU88575 - Improper input validation
CVE-2023-47100
CWE-20 High
No
No
12.0.0.8.0 16.04.2024 SB2024041718
SB2024041724
SB2024060504
and 8 more
#VU86623 - Use After Free
CVE-2024-23807
CWE-416 High
No
No
- 20.02.2024 SB2024022032
SB2024062836
SB2024071042
and 24 more
#VU83515 - Integer overflow
CVE-2023-37536
CWE-190 Medium
No
No
- 27.11.2023 SB2023112767
SB2023112803
SB2023112809
and 28 more
#VU70441 - Insufficient Verification of Data Authenticity
CVE-2021-37533
CWE-345 Low
No
No
- 20.12.2022 SB2022122007
SB2022123001
SB2023011876
and 82 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
- 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU65834 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31160
CWE-79 Low
No
No
- 27.07.2022 SB2022072727
SB2022100608
SB2022121119
and 44 more
#VU64913 - Incorrect Regular Expression
CVE-2022-31147
CWE-185 Medium
No
No
- 04.07.2022 SB2022070444
SB2023100327
SB2024011764


Showing elements 1 - 20 out of 61