Vulnerability in Oracle Communications Unified Inventory Management Portal
CVE-2018-2571

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists in the Oracle Communications Unified Inventory Management component, particularly within its Portal subcomponent. This flaw allows a low-privileged attacker with network access via HTTP to manipulate the inventory management system. Successful exploitation may lead to unauthorized changes or deletions of accessible data, as well as unauthorized access to sensitive information. This potential for data compromise emphasizes the urgent need for mitigation strategies to protect against these unauthorized interactions.

Affected Version(s)

Communications Unified Inventory Management 7.2.4.2.x

Communications Unified Inventory Management 7.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.