#VU103294 Improper input validation in Oracle Communications Order and Service Management - CVE-2025-21554
Published: January 24, 2025
Oracle Communications Order and Service Management
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Security component in Oracle Communications Order and Service Management. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.