Description
Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version
Any version
References
www.ericsson.com/en/about-us/security/psirt/cve-2024-25011