Impact
A flaw in Oracle Communications Cloud Native Core Security Edge Protection Proxy allows an attacker who can reach the proxy through ordinary HTTP traffic to perform unauthorized update, insert or delete operations on the proxy’s data and to read protected data. The vulnerability is easy to exploit once network access is obtained and does not require elevated privileges. It results in loss of integrity and confidentiality for the affected data. The weakness is rooted in improper access control.
Affected Systems
The vulnerability affects Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 26.1.200 and 25.2.201. Users running these builds should consider them vulnerable until a fix is applied.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates a moderate risk, with only confidentiality and integrity impacted. The EPSS reflects a very low probability of exploitation (<1%). The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exploit it by sending crafted HTTP requests to the exposed interface; no additional co‑existing vulnerabilities are required, and the attack is feasible for a low‑privileged network user.
OpenCVE Enrichment