Improper input validation in Oracle Communications Session Report Manager - CVE-2026-23903
Published: April 22, 2026
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Third Party (Apache Shiro) component in Oracle Communications Session Report Manager. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.
Affected software
Oracle Communications Element Manager