Unauthenticated Access Vulnerability in Oracle E-Business Suite's Content Manager
CVE-2019-2445

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

A vulnerability exists in Oracle E-Business Suite's Content Manager that enables an unauthenticated attacker with network access via HTTP to exploit the system. This flaw requires human interaction from a user other than the attacker to successfully compromise the Content Manager. While primarily affecting the Content Manager, the ramifications of successful exploitation can extend to other integrated products, potentially allowing unauthorized access to sensitive data. Attackers could gain the capability to update, insert, or delete data within the Content Manager, leading to significant data integrity and confidentiality issues.

Affected Version(s)

Content Manager 12.1.1

Content Manager 12.1.2

Content Manager 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.