Oracle Communications Order and Service Management
cpe:2.3:a:oracle:communications_order_and_service_management:*:*:*:*:*:*:*
- 7.4.0
- 7.4.1
- 7.5.0
A vulnerability has been identified in the Oracle Communications Order and Service Management product, specifically in versions 7.4.0, 7.4.1, and 7.5.0. This vulnerability, which resides in the Security component, is easily exploitable by low-privileged attackers with network access via HTTP. Successful exploitation allows unauthorized users to update, insert, or delete certain accessible data within Oracle Communications Order and Service Management. Additionally, it permits unauthorized read access to a subset of accessible data and the ability to cause a partial denial-of-service on the application.
Exploitation of this vulnerability could lead to unauthorized modification or deletion of data, unauthorized access to sensitive information, and a partial denial-of-service, causing some disruption to the application's availability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.