Email Center Vulnerability in Oracle E-Business Suite
CVE-2019-2491

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

The Oracle Email Center component of Oracle E-Business Suite features a vulnerability that can potentially be exploited by an unauthenticated attacker with network access via HTTP. This flaw necessitates human interaction, introducing a layer of complexity to exploitation. Although the vulnerability lies within the Email Center, successful attacks could lead to unauthorized data manipulation across the suite, impacting various accessible data repositories. Versions affected include multiple iterations from 12.1.1 through 12.2.8, necessitating immediate attention from users to mitigate possible unauthorized updates, inserts, or deletions of sensitive information.

Affected Version(s)

Email Center 12.1.1

Email Center 12.1.2

Email Center 12.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.