Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Oracle
Subscribe
|
Application Testing Suite
Subscribe
Banking Enterprise Collections
Subscribe
Banking Enterprise Originations
Subscribe
Banking Enterprise Product Manufacturing
Subscribe
Banking Platform
Subscribe
Business Process Management Suite
Subscribe
Clinical
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Network Integrity
Subscribe
Communications Service Broker
Subscribe
Communications Services Gatekeeper
Subscribe
Enterprise Repository
Subscribe
Financial Services Lending And Leasing
Subscribe
Financial Services Revenue Management And Billing Analytics
Subscribe
Flexcube Private Banking
Subscribe
Health Sciences Data Management Workbench
Subscribe
Hyperion Planning
Subscribe
Rapid Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Clearance Optimization Engine
Subscribe
Retail Markdown Optimization
Subscribe
Retail Sales Audit
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-10-15T18:50:07.530Z
Reserved: 2018-12-14T00:00:00
Link: CVE-2019-2904
Updated: 2024-08-04T19:03:43.365Z
Status : Modified
Published: 2019-10-16T18:15:27.560
Modified: 2024-11-21T04:41:46.483
Link: CVE-2019-2904
No data.
OpenCVE Enrichment
No data.
Weaknesses