Executive brief
A security vulnerability exists in the RTP Proxy component of Oracle Communications Converged Application Server, a platform used by telecommunications providers to manage multimedia sessions. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to take full control of the application. Such an attack could lead to a complete loss of data confidentiality and service availability, potentially impacting other integrated systems.
Technical details
A vulnerability in the RTP Proxy component of Oracle Communications Converged Application Server version 8.3 allows for a complete system takeover. The flaw is characterized by a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate security scope of the application. Exploitation is considered difficult (AC:H) and requires the attacker to already possess high-level privileges (PR:H) and local logon access to the infrastructure where the server executes. Successful exploitation results in a total compromise of confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Communications Converged Application Server 8.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published