Vulnerability in Oracle Workflow Component of Oracle E-Business Suite
CVE-2019-2925
4.3MEDIUM
Summary
An exploitable vulnerability exists in the Oracle Workflow component of the Oracle E-Business Suite that allows unauthorized access to data. This vulnerability takes advantage of a weakness that permits unauthenticated attackers with network access via HTTP to compromise the workflow operations. Successfully exploiting this vulnerability leads to unauthorized capabilities such as updating, inserting, or deleting accessible data within the Oracle Workflow. Notably, the exploitation requires user interaction from a party other than the attacker, increasing the complexity of successful attacks.
Affected Version(s)
Workflow 12.1.3
Workflow 12.2.3-12.2.8
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved