Impact
The vulnerability allows a low‑privileged user who has logged into the underlying infrastructure to compromise Oracle Utilities Network Management System. An attacker can successfully take control of the system, leading to full compromise of confidentiality, integrity, and availability.
Affected Systems
Oracle Utilities Network Management System from Oracle Corporation is affected. The impacted version ranges are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates high impact. The low EPSS score (<1%) implies the vulnerability is unlikely to be widely exploited yet, and it is not presently listed in the CISA KEV. The attack vector is local (AV:L) and requires low privileges with network access to the environment where the application runs. Because the vulnerability allows a local attacker to achieve system takeover, the potential damage is significant if the infrastructure is not properly segmented or monitored.
OpenCVE Enrichment