Unauthenticated Remote Access Vulnerability in Oracle E-Business Suite Wireless Component
CVE-2019-2828

9.6CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

An easily exploitable vulnerability exists in the Wireless component of the Oracle Field Service within the Oracle E-Business Suite, impacting versions from 12.1.1 to 12.2.8. An unauthenticated attacker can gain access via HTTP, requiring human interaction from another user. While primarily affecting the Oracle Field Service, successful exploitation can have significant repercussions on additional products within the suite, leading to potential unauthorized control and exposure of sensitive data. Organizations utilizing the affected versions should prioritize patching to mitigate potential attacks.

Affected Version(s)

Field Service 12.1.1 - 12.1.3

Field Service 12.2.3 - 12.2.8

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.