SQL Injection Vulnerability in Oracle E-Business Suite
CVE-2019-2546

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 January 2019

Summary

An SQL injection vulnerability exists in the Oracle Applications Manager component of Oracle E-Business Suite. This vulnerability allows an unauthenticated attacker with network access via HTTP to exploit the system, requiring human interaction from an external user. Successful exploitation could enable unauthorized updates, inserts, or deletions of sensitive data handled by the Oracle Applications Manager, potentially leading to significant integrity and availability impacts of the data. Affected versions include 12.1.1 to 12.2.8.

Affected Version(s)

Applications Manager 12.1.1

Applications Manager 12.1.2

Applications Manager 12.1.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.