CVE-2019-2483
CVSS 3.0 Score 8.2 of 10 (high)
Details
Summary
CVE-2019-2483 is a vulnerability affecting the Oracle iStore component of Oracle E-Business Suite, specifically versions 12.1.1 to 12.2.8. This easily exploitable issue enables unauthenticated attackers, with network access via HTTP, to compromise Oracle iStore. Successful attacks require human interaction but can result in significant impacts, such as unauthorized access to critical data or complete access to all Oracle iStore data, as well as unauthorized update, insert, or delete access to some data. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System (CVSS), is 8.2 for both Confidentiality and Integrity impacts. The attack vector is defined as Network (NV), the attack complexity is Low (L), and the privileges required are None (N), User Interaction (R), and Security Impact is High (H), Confidentiality (C) and Integrity (I) are affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.