Oracle E-Business Suite Content Vulnerability Affecting Multiple Versions
CVE-2019-3022

5.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

An unauthenticated vulnerability in Oracle Content Manager, part of Oracle E-Business Suite, allows attackers with network access to exploit this weakness via HTTP. The compromise can lead to unauthorized access, including the ability to update, insert, or delete accessible data within the Content Manager. Although primarily affecting Oracle Content Manager, the implications of successful exploitation may cascade to other components within the Oracle E-Business Suite ecosystem.

Affected Version(s)

Content Manager 12.1.1-12.1.3

Content Manager 12.2.3-12.2.9

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.