First published: Tue Jan 21 2025(Updated: )
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Communications Order and Service Management | >=7.4.0<=7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-21554 is classified as an easily exploitable vulnerability that poses a risk of unauthorized access.
To mitigate CVE-2025-21554, upgrade to a version of Oracle Communications Order and Service Management that is not affected, specifically above version 7.5.0.
CVE-2025-21554 affects versions 7.4.0, 7.4.1, and 7.5.0 of Oracle Communications Order and Service Management.
Yes, CVE-2025-21554 can be exploited by an unauthenticated attacker with network access.
CVE-2025-21554 specifically impacts the Security component of the Oracle Communications Order and Service Management product.