Improper input validation in Oracle Communications Billing and Revenue Management - CVE-2025-26333

 

Improper input validation in Oracle Communications Billing and Revenue Management - CVE-2025-26333

Published: January 20, 2026


Vulnerability identifier: #VU121709
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26333
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Platform (BSAFE Crypto-J) component in Oracle Communications Billing and Revenue Management. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


Affected software

Oracle Communications Billing and Revenue Management
Oracle Communications Network Integrity
Oracle Communications Unified Inventory Management
JD Edwards EnterpriseOne Tools
Oracle Security Service
Oracle Application Testing Suite
Oracle Retail Service Backbone
Oracle Fusion Middleware
Oracle Retail Predictive Application Server
Oracle Retail Integration Bus

How to mitigate CVE-2025-26333

Install updates from vendor's website.


External References

Related Security Bulletins