CVE-2019-2858: Medium severity oracle identity management suite vulnerability
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Advanced Console). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-2858?
CVE-2019-2858 is a vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware.
Which versions of Oracle Identity Manager are affected by CVE-2019-2858?
The affected versions are 11.1.2.3.0 and 12.2.1.3.0.
What is the severity rating of CVE-2019-2858?
The severity rating is medium with a value of 4.3.
How can CVE-2019-2858 be exploited?
The vulnerability can be exploited by a low privileged attacker with network access via HTTP.
Where can I find more information about CVE-2019-2858?
You can find more information about CVE-2019-2858 at the following link: http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html