Impact
A vulnerability exists in the Mobile component of Oracle Utilities Network Management System that permits a low‑privileged attacker who can reach the component over HTTP to read a subset of data that should be restricted. The flaw does not enable code execution or privilege escalation; it simply allows the attacker to view confidential information through an unauthorized read path. The weakness is a classic example of improper authorization, as indicated by the CWE-284 identifier.
Affected Systems
Oracle Utilities Network Management System is impacted. The affected release range includes 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.1.0 through 2.6.0.1.12, 2.6.0.2.0 through 2.6.0.2.8, and 25.12.0.0.0 through 25.12.0.0.2.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 marks the vulnerability as moderate, driven primarily by a confidentiality impact. The EPSS score of < 1% indicates that attacks are expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network connectivity to the HTTP port exposed by the Mobile component and low privileges on the target system. No additional access or user interaction is required beyond the initial HTTP request, making the exploit path straightforward once network access is established.
OpenCVE Enrichment