Vulnerability in Networking Component of Oracle Enterprise Manager Products Suite
CVE-2019-2728
4.3MEDIUM
Summary
A vulnerability exists in the Networking component of Oracle's Enterprise Manager Ops Center, affecting versions 12.3.3 and 12.4.0. This flaw allows a low privileged attacker with network access via HTTP to execute unauthorized operations. Successful exploitation could lead to the attacker gaining the ability to update, insert, or delete certain data within Enterprise Manager Ops Center, posing significant risks to data integrity.
Affected Version(s)
Enterprise Manager Ops Center 12.3.3
Enterprise Manager Ops Center 12.4.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved