Impact
A flaw in the security component of Oracle Utilities Network Management System enables an attacker with only low privilege and direct HTTP access to perform unauthorized update, insert, delete or read operations on data stored by the system. The vulnerability is exploitable without privileged credentials, but it requires manual interaction by a separate, non‑attacker user to trigger the action. Successful exploitation can result in altered or removed data and the disclosure of a subset of system data, impacting both data integrity and confidentiality.
Affected Systems
The vulnerability affects Oracle Utilities Network Management System versions 2.4.0.1.0 through 2.4.0.1.32, 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.2.0 through 2.6.0.2.7, and the 25.12.0.0.0 release. These versions are part of the Oracle Utilities Applications stack.
Risk and Exploitability
The CVSS base score of 4.6 indicates moderate risk; the EPSS score of less than 1% shows a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires network reachability via HTTP and a separate user action, so the attack surface is limited. Nonetheless, because the outcome includes unauthorized data modification and partial data disclosure, organizations should consider the exposed data as potentially sensitive.
OpenCVE Enrichment