7.5
CVSSv2

CVE-2019-2904

Published: 16/10/2019 Updated: 18/05/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle application testing suite 12.5.0.3

oracle application testing suite 13.1.0.1

oracle application testing suite 13.2.0.1

oracle application testing suite 13.3.0.1

oracle banking enterprise collections 2.7.0

oracle banking enterprise collections 2.8.0

oracle banking enterprise originations 2.7.0

oracle banking enterprise originations 2.8.0

oracle banking enterprise product manufacturing 2.7.0

oracle banking enterprise product manufacturing 2.8.0

oracle banking platform 2.4.0

oracle banking platform 2.4.1

oracle banking platform 2.5.0

oracle banking platform 2.6.0

oracle banking platform 2.6.1

oracle banking platform 2.6.2

oracle banking platform 2.7.0

oracle banking platform 2.7.1

oracle banking platform 2.9.0

oracle business process management suite 12.2.1.3.0

oracle business process management suite 12.2.1.4.0

oracle clinical 5.2

oracle communications diameter signaling router

oracle communications network integrity

oracle communications service broker 6.0

oracle communications service broker 6.1

oracle communications services gatekeeper 6.0

oracle communications services gatekeeper 6.1

oracle enterprise repository 11.1.1.7.0

oracle financial services lending and leasing 12.5.0

oracle financial services lending and leasing

oracle financial services revenue management and billing analytics 2.6

oracle financial services revenue management and billing analytics 2.7

oracle financial services revenue management and billing analytics 2.8

oracle flexcube private banking 12.0.0

oracle flexcube private banking 12.1.0

oracle health sciences data management workbench 2.4

oracle health sciences data management workbench 2.5

oracle hyperion planning 11.1.2.4

oracle rapid planning 12.1.3

oracle retail assortment planning 15.0.3.0

oracle retail assortment planning 16.0.3.0

oracle retail clearance optimization engine 13.4

oracle retail clearance optimization engine 14.0.3

oracle retail clearance optimization engine 14.0.5

oracle retail markdown optimization 13.4

oracle retail sales audit 15.0.3

oracle retail sales audit 16.0.2