Vulnerability in Oracle E-Business Suite Print Server Component
CVE-2019-2668

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A network access vulnerability in the Print Server component of Oracle E-Business Suite enables unauthenticated attackers to exploit the Oracle One-to-One Fulfillment functionality. This exploitation can potentially lead to unauthorized access to sensitive data, compromising the integrity of crucial information. A successful attack requires an interactive step from a third party, posing significant risks to additional products tied to this component. Attackers could gain extensive control over accessible data, including update, insert, and delete commands, leading to significant security breaches for organizations utilizing these affected versions.

Affected Version(s)

One-to-One Fulfillment 12.1.1 - 12.1.3

One-to-One Fulfillment 12.2.3 - 12.2.8

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.