7.8
CVE-2026-83342
- EPSS 0.13%
- Veröffentlicht 15.09.2026 20:18:47
- Zuletzt bearbeitet 17.09.2026 13:16:49
- Erkennungen
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and 25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOracle Corporation
≫
Produkt
Oracle Utilities Network Management System
Version <=
2.4.0.1.33
Version
2.4.0.1.0
Status
affected
Version <=
2.5.0.1.19
Version
2.5.0.1.0
Status
affected
Version <=
2.5.0.2.13
Version
2.5.0.2.0
Status
affected
Version <=
2.6.0.12B
Version
2.6.0.1.0
Status
affected
Version <=
2.6.0.2.10A
Version
2.6.0.2.0
Status
affected
Version <=
25.12.0.0.3
Version
25.12.0.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.027 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Oracle | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://www.oracle.com/security-alerts/cspusep2026.html