Impact
A flaw in the third‑party component of Oracle Communications Unified Inventory Management allows an unauthenticated attacker who can reach the HTTP interface to create, delete, or alter critical data, or to obtain full access to all inventory data. The vulnerability results in high confidentiality and integrity loss, as indicated by a CVSS base score of 7.4 with high impact on both categories.
Affected Systems
The product affected is Oracle Communications Unified Inventory Management. Versions 7.5.0, 7.5.1, 7.6.0 through 7.8.0, and 8.0.1 are impacted.
Risk and Exploitability
The CVSS vector shows a network attack with high complexity, no privileges, and no user interaction, meaning the vulnerability can be exploited remotely over HTTP. The EPSS score is low (<1%), indicating a low but nonzero likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. While exploitation probability is modest, the potential for significant data loss warrants prompt remediation.
OpenCVE Enrichment