Unauthenticated Access Vulnerability in Oracle Argus Safety by Oracle
CVE-2019-2431

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

An unauthenticated access vulnerability exists in the Oracle Argus Safety component of Oracle Health Sciences Applications, affecting versions 8.1 and 8.2. This vulnerability may allow an attacker with network access via HTTP to exploit the affected system. Although the exploitation is difficult and requires human interaction from another individual, successful exploitation can lead to unauthorized creation, deletion, or modifications of critical data, impacting all data accessible through Oracle Argus Safety. Attackers can significantly influence additional products linked to this component, emphasizing the need for vigilance in maintaining system security.

Affected Version(s)

Argus Safety 8.1

Argus Safety 8.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.