PT-2025-4276 · Oracle · Oracle Communications Order/Service Management
Published
2025-01-21
·
Updated
2025-06-20
·
CVE-2025-21554
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Communications Order and Service Management versions 7.4.0 through 7.5.0
Description
The issue is related to insufficient authorization procedures in the Security component of Oracle Communications Order and Service Management. This can be exploited by a remote attacker using HTTP requests to disclose protected information. Successful attacks may result in unauthorized read access to a subset of accessible data.
Recommendations
For versions 7.4.0, 7.4.1, and 7.5.0, consider restricting access to the Security component until a patch is available.
As a temporary workaround, limit HTTP access to minimize the risk of exploitation.
Avoid using sensitive data in the affected system until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Communications Order/Service Management