Impact
The flaw in Oracle Communications Unified Inventory Management enables an unauthenticated HTTP client to retrieve confidential data without any credentials, exploiting an improper access control weakness (CWE-284). Because the vulnerability does not require a user context, any network‑connected attacker can send requests to the service and read protected content, resulting in confidentiality loss.
Affected Systems
Oracle Communications Unified Inventory Management versions 7.5.0 through 7.5.1, 7.6.0 through 7.8.0, and 8.0.1 are vulnerable. Users running these releases, regardless of administrative settings, are susceptible to the attack.
Risk and Exploitability
The CVSS base score of 7.5 signals a moderate to high risk, while the EPSS score of < 1% indicates a low probability of exploitation in current data. The vulnerability is not listed in CISA’s KEV catalog. The attack can be launched remotely from any network location that can reach the HTTP interface, requiring no authentication and yielding full exposure of all data available through the application.
OpenCVE Enrichment