Vulnerability in Oracle E-Business Suite Service Contracts Component
CVE-2019-2622

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

A vulnerability exists in the Oracle E-Business Suite's Service Contracts component that allows an unauthenticated attacker to exploit the system through HTTP. The vulnerability requires interaction from a user other than the attacker, which could lead to unauthorized data manipulation, including updates, inserts, or deletions within Oracle Service Contracts. This issue affects several versions of the product, posing significant risks not only to the service contracts but potentially impacting additional interconnected components.

Affected Version(s)

Service Contracts 12.1.1

Service Contracts 12.1.2

Service Contracts 12.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.