Impact
The vulnerability resides in the mobile component of Oracle Utilities Network Management System. It allows an unauthenticated attacker with network access via HTTP to perform unauthorized update, insert, delete operations and read access to a subset of data. The flaw is easily exploitable and its CVSS 3.1 base score of 7.2 reflects confidentiality and integrity impact with scope change, meaning additional products may also be affected.
Affected Systems
The affected product is Oracle Utilities Network Management System under Oracle Utilities Applications, specifically its Mobile component. Versions 2.5.0.1.0 through 2.5.0.1.17, 2.5.0.2.0 through 2.5.0.2.11, 2.6.0.1.0 through 2.6.0.1.12, 2.6.0.2.0 through 2.6.0.2.8, and 25.12.0.0.0 through 25.12.0.0.2 are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating moderate to high severity. EPSS is < 1 %, showing a low probability of exploitation currently, and it is not listed in CISA's KEV catalog. The likely attack vector is unauthenticated access over HTTP, meaning it can be triggered by anyone on the network path. Successful exploitation enables attackers to modify or delete critical configuration data and read sensitive information, potentially cascading to other products due to the scope change. Because no workaround is provided, immediate remediation is recommended.
OpenCVE Enrichment