V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-2904
CVE
Critical

Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affe…

CVSS
9.8
Critical
EPSS
0.14
p96
Published
2019-01-01
Updated
2019-01-01
Description

Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Tags · CWE
Pre-auth
Affected products
Application_testing_suiteBanking_enterprise_collectionsBanking_enterprise_originationsBanking_enterprise_product_manufacturingBanking_platformBusiness_process_management_suiteClinicalCommunications_diameter_signaling_router 8.0.0.0–8.4.0.5Communications_network_integrity 7.3.2–7.3.6Communications_service_brokerCommunications_services_gatekeeperEnterprise_repositoryFinancial_services_lending_and_leasing 14.1.0–14.2.0Financial_services_lending_and_leasingFinancial_services_revenue_management_and_billing_analyticsFlexcube_private_bankingHealth_sciences_data_management_workbenchHyperion_planningRapid_planningRetail_assortment_planningRetail_clearance_optimization_engineRetail_markdown_optimizationRetail_sales_audit
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.143 · p96
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
application_testing_suite*Tracked
banking_enterprise_collections*Tracked
banking_enterprise_originations*Tracked
banking_enterprise_product_manufacturing*Tracked
banking_platform*Tracked
business_process_management_suite*Tracked
clinical*Tracked
communications_diameter_signaling_router*Tracked
communications_network_integrity*Tracked
communications_service_broker*Tracked
communications_services_gatekeeper*Tracked
enterprise_repository*Tracked
financial_services_lending_and_leasing*Tracked
financial_services_revenue_management_and_billing_analytics*Tracked
flexcube_private_banking*Tracked
health_sciences_data_management_workbench*Tracked
hyperion_planning*Tracked
rapid_planning*Tracked
retail_assortment_planning*Tracked
retail_clearance_optimization_engine*Tracked
Showing first 20 of 22
Source databases
CVE
Related vulnerabilities