Vulnerability in Oracle Commerce Platform of Oracle
CVE-2019-2712

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 April 2019

Summary

The vulnerability in the Oracle Commerce Platform, specifically within the Dynamo Application Framework, exposes supported versions 11.2.0.3 and 11.3.1 to potential attacks. An attacker can exploit this weakness remotely through HTTP, requiring minimal user interaction. Successful exploitation may allow the attacker to execute unauthorized operations such as updates, inserts, or deletions of data within the platform. Moreover, it can facilitate unauthorized reading of sensitive data, thus compromising the confidentiality and integrity of the information stored on Oracle Commerce. Organizations using affected versions should implement necessary security measures to mitigate these risks.

Affected Version(s)

Commerce Platform 11.2.0.3

Commerce Platform 11.3.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.