Oracle E-Business Suite Vulnerability in Installed Base Product
CVE-2019-3024
4.7MEDIUM
Summary
An unauthenticated attacker with network access can exploit a vulnerability in the Oracle Installed Base component of Oracle E-Business Suite, specifically affecting versions 12.2.3 to 12.2.9. The vulnerability requires human interaction from a third party to successfully initiate an attack. An exploit can lead to unauthorized modifications to accessible data within the Oracle Installed Base, potentially impacting other interconnected products. Proper security measures are essential to mitigate risks associated with this vulnerability.
Affected Version(s)
Installed Base 12.2.3-12.2.9
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved