Unauthenticated Access Vulnerability in Oracle E-Business Suite Payment Component
CVE-2019-2783

5.8MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
23 July 2019

Summary

An unauthenticated access vulnerability exists in the Oracle Payments component of the Oracle E-Business Suite, which impacts a range of versions. This weakness allows an attacker with network access via HTTP to compromise sensitive data without authentication. Although the vulnerability is specific to Oracle Payments, an exploit could lead to unauthorized read access to confidential information stored within. The impact is significant as it may affect not only the payments component but could also extend to other integrated products within the Oracle E-Business Suite. Users are urged to apply security patches to mitigate potential risks.

Affected Version(s)

Payments 12.1.1 - 12.1.3

Payments 12.2.3 - 12.2.8

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.