CVE-2020-9546 | Oracle Communications Network Charging/Control up to 12.0.3 Installer deserialization (Nessus ID 216682)
A vulnerability was found in Oracle Communications Network Charging and Control 6.0.1/12.0.0/12.0.1/12.0.2/12.0.3. It has been classified as critical. The impacted element is an unknown function of the component Installer. Performing a manipulation results in deserialization.
This vulnerability is identified as CVE-2020-9546. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.