Unauthorized Access Vulnerability in Oracle Communications Operations Monitor
CVE-2022-21401

6.6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability in Oracle Communications Operations Monitor exposes the product to potential unauthorized access, allowing an attacker with high privileges and network access to manipulate sensitive data. This includes the ability to unauthorized update, insert, or delete data, along with unauthorized reading of accessible data. Additionally, the vulnerability can lead to a partial denial of service, impacting the availability of the affected operations monitor. It highlights the importance of securing network connections and maintaining updated software versions to mitigate potential exploitation.

Affected Version(s)

Communications Operations Monitor 3.4

Communications Operations Monitor 4.2

Communications Operations Monitor 4.3

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.