Remote Code Execution Vulnerability in Oracle SOA Suite by Oracle
CVE-2019-2572
5.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 23 April 2019
Summary
The vulnerability affects Oracle SOA Suite within Oracle Fusion Middleware, specifically targeting the Fabric Layer component. It allows an unauthenticated attacker with network access to exploit the system via HTTP. Successful exploitation can lead to the unauthorized reading of sensitive data contained within Oracle SOA Suite, thereby compromising its confidentiality. Organizations using affected versions should assess their exposure and implement necessary security measures.
Affected Version(s)
Business Process Management Suite 11.1.1.9.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved