Oracle Argus Safety Vulnerability in Health Sciences Applications
CVE-2019-2432

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

A low-privileged attacker can exploit a vulnerability in Oracle Argus Safety, impacting the application's login component. Found in versions 8.1 and 8.2, this vulnerability poses a risk of unauthorized access, manipulation, and potential exposure of sensitive data. Although the exploit is considered difficult, successful attacks could enable attackers to update, insert, or delete data, as well as gain unauthorized read access to certain datasets. This may not only affect Oracle Argus Safety but could also have serious implications for other integrated Oracle Health Sciences products.

Affected Version(s)

Argus Safety 8.1

Argus Safety 8.2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.