CVE-2019-2904
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected (48)
Products: Oracle: Application Testing Suite, Banking Enterprise Collections, Banking Enterprise Originations, Banking Enterprise Product Manufacturing, Banking Platform, Business Process Management Suite, Clinical, Communications Diameter Signaling Router, Communications Network Integrity, Communications Service Broker, Communications Services Gatekeeper, Enterprise Repository, Financial Services Lending And Leasing, Financial Services Revenue Management And Billing Analytics, Flexcube Private Banking, Health Sciences Data Management Workbench, Hyperion Planning, Rapid Planning, Retail Assortment Planning, Retail Clearance Optimization Engine, Retail Markdown Optimization, Retail Sales Audit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.5.0.3 | |
| Version 2.7.0 | |
| Version 2.7.0 | |
| Version 2.7.0 | |
| Version 2.4.0 | |
| Version 12.2.1.3.0 | |
| Version 5.2 | |
| From 8.0.0.0 to 8.4.0.5 | |
| From 7.3.2 to 7.3.6 | |
| Version 6.0 | |
| Version 6.0 | |
| Version 11.1.1.7.0 | |
| From 14.1.0 to 14.2.0 | |
| Version 2.6 | |
| Version 12.0.0 | |
| Version 2.4 | |
| Version 11.1.2.4 | |
| Version 12.1.3 | |
| Version 15.0.3.0 | |
| Version 13.4 | |
| Version 13.4 | |
| Version 15.0.3 |
References (14)
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.