Oracle E-Business Suite Vulnerability in Installed Base Product
CVE-2019-3024

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

An unauthenticated attacker with network access can exploit a vulnerability in the Oracle Installed Base component of Oracle E-Business Suite, specifically affecting versions 12.2.3 to 12.2.9. The vulnerability requires human interaction from a third party to successfully initiate an attack. An exploit can lead to unauthorized modifications to accessible data within the Oracle Installed Base, potentially impacting other interconnected products. Proper security measures are essential to mitigate risks associated with this vulnerability.

Affected Version(s)

Installed Base 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.