CVE-2025-21554: Medium severity oracle communications order and service management vulnerability
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21554?
CVE-2025-21554 is classified as an easily exploitable vulnerability that poses a risk of unauthorized access.
How do I fix CVE-2025-21554?
To mitigate CVE-2025-21554, upgrade to a version of Oracle Communications Order and Service Management that is not affected, specifically above version 7.5.0.
What versions of Oracle Communications Order and Service Management are affected by CVE-2025-21554?
CVE-2025-21554 affects versions 7.4.0, 7.4.1, and 7.5.0 of Oracle Communications Order and Service Management.
Can an attacker exploit CVE-2025-21554 without authentication?
Yes, CVE-2025-21554 can be exploited by an unauthenticated attacker with network access.
What components of Oracle Communications Applications are impacted by CVE-2025-21554?
CVE-2025-21554 specifically impacts the Security component of the Oracle Communications Order and Service Management product.