Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.oracle.com/security-alerts/cpujan2025.html |     | 
History
                    Wed, 22 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-346 | |
| Metrics | ssvc 
 | 
Tue, 21 Jan 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). | |
| First Time appeared | Oracle Oracle communications Order And Service Management | |
| CPEs | cpe:2.3:a:oracle:communications_order_and_service_management:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_order_and_service_management:7.4.1:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:* | |
| Vendors & Products | Oracle Oracle communications Order And Service Management | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: oracle
Published: 2025-01-21T20:53:13.104Z
Updated: 2025-01-22T18:14:29.608Z
Reserved: 2024-12-24T23:18:54.773Z
Link: CVE-2025-21542
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-01-22T18:14:24.366Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-21T21:15:20.420
Modified: 2025-06-20T16:57:56.907
Link: CVE-2025-21542
 Redhat
                        Redhat
                    No data.