CVE-2025-21544
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-21544 is a vulnerability affecting Oracle Communications Order and Service Management in versions 7.4.0, 7.4.1, and 7.5.0. This issue, located within the Security component, enables a low-privileged attacker with network access to compromise the system via HTTP. Successfully exploited attacks necessitate human interaction and may expand the attack surface to other products. The consequences of this vulnerability can result in unauthorized modification or deletion of some data, as well as unauthorized reading of a subset of data. The Base Score, according to the Common Vulnerability Scoring System version 3.1, is 5.4, with impacts on both confidentiality and integrity.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle Communications Order and Service Management
Affected Vendors
- BonqDAO