Vulnerability in Oracle Identity Manager Component of Oracle Fusion Middleware
CVE-2019-2858
4.3MEDIUM
Summary
The vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware, specifically the Advanced Console subcomponent, allows low-privileged attackers with network access to exploit the system via HTTP. This exploitation can lead to unauthorized updates, inserts, or deletions of data accessible by Oracle Identity Manager. Supported versions affected include 11.1.2.3.0 and 12.2.1.3.0. Security measures should be taken to mitigate the risk of unauthorized data manipulation.
Affected Version(s)
Identity Manager 11.1.2.3.0
Identity Manager 12.2.1.3.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved