CVE-2024-25011: Ericsson Catalog Manager
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue.
Affected products
- Ericsson Ericsson Catalog Manager: up to and including 22.6
- Ericsson Ericsson Order Care: up to and including 22.6
Published 2025-09-18. Last modified 2026-06-17.