First published: Tue Apr 15 2025(Updated: )
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 5.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Communications Order and Service Management | >=7.4.0<=7.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30729 is considered an easily exploitable vulnerability that allows low privileged attackers to gain unauthorized access.
To fix CVE-2025-30729, users should upgrade their Oracle Communications Order and Service Management product to the latest patched version.
CVE-2025-30729 affects Oracle Communications Order and Service Management versions 7.4.0, 7.4.1, and 7.5.0.
CVE-2025-30729 impacts the security component of the Oracle Communications Order and Service Management product.
CVE-2025-30729 can be exploited by low privileged attackers with network access via HTTP.