Unauthenticated Access Vulnerability in Oracle E-Business Suite Mobile Field Service
CVE-2019-2485

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

The vulnerability in Oracle Mobile Field Service within the Oracle E-Business Suite allows an unauthenticated attacker with network access to compromise the system. Exploitation requires human interaction from a person other than the attacker, which makes it uniquely concerning. The access attained can lead to unauthorized updates, inserts, or deletions of accessible data, posing significant risks to data integrity and security across related products.

Affected Version(s)

Mobile Field Service 12.1.1

Mobile Field Service 12.1.2

Mobile Field Service 12.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.