Executive brief
Oracle Communications Unified Inventory Management is a system used by telecommunications providers to track and manage communications infrastructure inventory. A vulnerability allows unauthenticated attackers on the network to bypass security controls via HTTP and gain unauthorized access to sensitive data stored within the system, potentially exposing critical operational and customer information.
Technical details
The vulnerability is an authentication bypass in the Security Component of Oracle Communications Unified Inventory Management that allows unauthenticated attackers to access critical data. The flaw can be exploited over the network via HTTP without requiring user interaction or special privileges. An attacker can achieve complete unauthorized access to all data accessible through the application. The vulnerability affects versions 7.5.0 through 7.5.1, 7.6.0 through 8.0.0, and 8.0.1. Patch availability is not confirmed in the available advisory references.
Affected products
- Oracle Communications Unified Inventory Management 7.5.0-7.5.1, 7.6.0-8.0.0, 8.0.1
Timeline
- 2026-08-18: disclosed