Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Merchandising accessible data as well as unauthorized read access to a subset of Oracle Commerce Merchandising accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: oracle
Published: 2019-04-23T18:16:45
Updated: 2024-10-02T15:53:32.691Z
Reserved: 2018-12-14T00:00:00
Link: CVE-2019-2713

Updated: 2024-08-04T18:56:45.649Z

Status : Modified
Published: 2019-04-23T19:32:56.990
Modified: 2024-11-21T04:41:24.870
Link: CVE-2019-2713

No data.