PT-2025-38311 · Ericsson · Ericsson Order Care Apis+1

Published

2025-09-18

·

Updated

2025-09-19

·

CVE-2024-25011

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ericsson Catalog Manager and Ericsson Order Care APIs (affected versions not specified)
Description Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default, leading to an information disclosure issue. Authentication checks can be configured to remediate the issue.
Recommendations Configure authentication checks for the Ericsson Catalog Manager and Ericsson Order Care APIs.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-25011

Affected Products

Ericsson Catalog Manager
Ericsson Order Care Apis