Impact
The Oracle Communications Unified Inventory Management product contains a flaw in its security component that allows a low‑privileged attacker with network access via HTTP to gain unauthorized access to critical data. Successful exploitation can result in full data access and the ability to create, modify, or delete records, thereby compromising both confidentiality and integrity of the system's data set.
Affected Systems
Affected versions include Oracle Communications Unified Inventory Management 7.5.0, 7.5.1, 7.6.0, 7.7.0, 7.8.0, and 8.0.1. The vulnerability is present in the Security component that processes HTTP requests from clients connected to the product's web interface.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a high impact on confidentiality and a moderate impact on integrity. The EPSS score of less than 1% indicates that the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. However, because the attack can be performed over the network using HTTP and requires minimal privileges, an attacker could gain significant access to sensitive data or alter records if the patch is not applied.
OpenCVE Enrichment