Unauthenticated Access Vulnerability in Oracle Retail Applications
CVE-2019-2424
7.3HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 23 April 2019
What is CVE-2019-2424?
This vulnerability affects the Oracle Retail Convenience Store Back Office component of Oracle Retail Applications, specifically in its Level 3 Maintenance Functions. An unauthenticated attacker with network access via HTTP can exploit this vulnerability, potentially resulting in unauthorized updates, inserts, or deletions of certain data within the system. Additionally, it enables unauthorized read access to some of the accessible data and may lead to a partial denial of service, compromising the functionality of the Oracle Retail Convenience Store Back Office.
Affected Version(s)
Retail Convenience Store Back Office 3.6