Impact
The vulnerability in Oracle Communications Cloud Native Core Security Edge Protection Proxy allows an attacker with low privileges and network access via HTTP to gain unauthorized control over critical data stored or served by the proxy. Successful exploitation can lead to unauthorized creation, deletion, or modification of data, and can provide full read access to all data accessible through the proxy. Because the flaw impacts confidentiality and integrity, it poses a significant risk to data integrity and privacy even though availability is not directly affected.
Affected Systems
Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 25.2.201 and 26.1.200 are affected. Any environment running these versions without the vendor’s fix is vulnerable. The description notes a scope change, implying that neighboring components in an Oracle Communications installation may also be compromised when the proxy is exploited.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, with remote access via HTTP, high attack complexity, low privilege exploitation, and no user interaction required. The EPSS score of less than 1% suggests a very low, but nonzero, current exploitation probability. The vulnerability is not registered in the CISA KEV catalog. Although the attack requires only HTTP network connectivity and low privileges, the potential for extensive data alteration and theft demands rapid remediation.
OpenCVE Enrichment