CVE-2019-2904
Published on: 10/16/2019 12:00:00 AM UTC
Last Modified on: 05/18/2021 12:58:00 PM UTC
Certain versions of Application Development Framework from Oracle contain the following vulnerability:
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2019-2904 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Oracle Corporation - Enterprise Repository version = 11.1.1.7.0
- Affected Vendor/Software:
Oracle Corporation - Rapid Planning version = 12.1.3
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 7.5 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - July 2020 | www.oracle.com text/html |
![]() |
Oracle Critical Patch Update Advisory - April 2021 | www.oracle.com text/html |
![]() |
Oracle Critical Patch Update Advisory - October 2019 | Patch Vendor Advisory www.oracle.com text/html |
![]() |
Oracle Critical Patch Update Advisory - April 2020 | www.oracle.com text/html |
![]() |
ZDI-19-1024 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
Oracle Critical Patch Update Advisory - January 2020 | www.oracle.com text/html |
![]() |
Oracle Critical Patch Update Advisory - October 2020 | www.oracle.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:oracle:application_development_framework:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_development_framework:12.1.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_development_framework:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_development_framework:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_development_framework:12.1.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_development_framework:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_testing_suite:13.1.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_collections:2.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_collections:2.8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_originations:2.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_originations:2.8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_enterprise_product_manufacturing:2.8.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.4.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.6.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.6.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:clinical:5.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_network_integrity:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_services_gatekeeper:6.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_services_gatekeeper:6.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_service_broker:6.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_service_broker:6.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_lending_and_leasing:12.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_lending_and_leasing:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.6:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.7:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:financial_services_revenue_management_and_billing_analytics:2.8:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:health_sciences_data_management_workbench:2.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:health_sciences_data_management_workbench:2.5:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:hyperion_planning:11.1.2.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:jdeveloper:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:rapid_planning:12.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_assortment_planning:15.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_assortment_planning:16.0.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_clearance_optimization_engine:13.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_clearance_optimization_engine:14.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_clearance_optimization_engine:14.0.5:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_markdown_optimization:13.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_sales_audit:15.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_sales_audit:16.0.2:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|