Executive brief
Oracle Communications Unified Inventory Management is a system used by telecommunications operators to track and manage network inventory and assets. A flaw in the product allows unauthenticated attackers to gain unauthorized access via HTTP, enabling them to view, modify, or delete critical network inventory data without authentication. This could allow attackers to disrupt service operations, tamper with network configurations, or steal sensitive operator information.
Technical details
The vulnerability is an authentication bypass or authorization flaw in Oracle Communications Unified Inventory Management that allows unauthenticated attackers with network access to the HTTP interface to access and modify sensitive data. The attack requires no user interaction and presents difficult exploitation constraints (likely specific request formatting or race conditions). Successful exploitation results in unauthorized read and write access to critical inventory data. Affected versions include 7.5.0, 7.5.1, 7.6.0–7.8.0, and 8.0.1. No public exploit has been documented in the wild as of the advisory date.
Affected products
- Oracle Communications Unified Inventory Management 7.5.0, 7.5.1, 7.6.0-7.8.0, 8.0.1
Timeline
- 2026-08-18: disclosed