Unauthenticated Access Vulnerability in Oracle E-Business Suite's Print Server
CVE-2019-2654

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

A vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite, specifically within the Print Server subcomponent, allows an unauthenticated attacker with network access via HTTP to compromise the system. This flaw requires user interaction from a third party to exploit effectively. Although the issue resides in Oracle One-to-One Fulfillment, successful attacks can have a broader impact, potentially granting unauthorized access to sensitive data. Attackers can manipulate data within Oracle One-to-One Fulfillment, including unauthorized updates, inserts, or deletions. Exploiting this vulnerability could lead to significant confidentiality and integrity concerns for affected organizations.

Affected Version(s)

One-to-One Fulfillment 12.1.1

One-to-One Fulfillment 12.1.2

One-to-One Fulfillment 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.