Unauthorized Data Access Vulnerability in Oracle Communications Applications
CVE-2018-2570
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 January 2018
What is CVE-2018-2570?
A vulnerability exists in the Oracle Communications Unified Inventory Management component, allowing a low-privileged attacker with network access to HTTP to compromise the system. This exploitation can lead to unauthorized change capabilities (update, insert, delete) as well as the ability to read certain data that should remain secure. The vulnerability also opens up possibilities for partial denial of service attacks, affecting the overall availability of the Oracle Communications Unified Inventory Management system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Communications Unified Inventory Management 7.2.4.2.x
Communications Unified Inventory Management 7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved