Improper Access Control Vulnerability in Oracle Demantra Demand Management
CVE-2019-2733
4.3MEDIUM
Summary
An improper access control vulnerability exists in Oracle Demantra Demand Management, allowing low privileged attackers with network access via HTTP to compromise the system. This flaw permits unauthorized manipulation, including the ability to update, insert, or delete data within the application. The vulnerability affects version 7.3.1.5.2 of the software, posing a risk to data integrity and security.
Affected Version(s)
Demantra Demand Management 7.3.1.5.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved