2019-10-16 18:01:37 +00:00
{
2020-01-15 20:01:19 +00:00
"CVE_data_meta" : {
"ASSIGNER" : "secalert_us@oracle.com" ,
"ID" : "CVE-2019-2904" ,
"STATE" : "PUBLIC"
2019-10-16 18:01:37 +00:00
} ,
2020-01-15 20:01:19 +00:00
"affects" : {
"vendor" : {
"vendor_data" : [
2019-10-16 18:01:37 +00:00
{
2020-07-14 13:34:15 -07:00
"product" : {
"product_data" : [
{
"product_name" : "Banking Enterprise Default Management" ,
"version" : {
"version_data" : [
{
"version_value" : "2.7.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.8.0" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Banking Enterprise Originations" ,
"version" : {
"version_data" : [
{
"version_value" : "2.7.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.8.0" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Banking Enterprise Product Manufacturing" ,
"version" : {
"version_data" : [
{
"version_value" : "2.7.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.8.0" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Banking Platform" ,
"version" : {
"version_data" : [
{
"version_value" : "2.4.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.4.1" ,
"version_affected" : "="
} ,
{
"version_value" : "2.5.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.6.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.6.1" ,
"version_affected" : "="
} ,
{
"version_value" : "2.6.2" ,
"version_affected" : "="
} ,
{
"version_value" : "2.7.0" ,
"version_affected" : "="
} ,
{
"version_value" : "2.7.1" ,
"version_affected" : "="
} ,
{
"version_value" : "2.9.0" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Communications Service Broker" ,
"version" : {
"version_data" : [
{
"version_value" : "6.0" ,
"version_affected" : "="
} ,
{
"version_value" : "6.1" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Communications Services Gatekeeper" ,
"version" : {
"version_data" : [
{
"version_value" : "6.0" ,
"version_affected" : "="
} ,
{
"version_value" : "6.1" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "FLEXCUBE Private Banking" ,
"version" : {
"version_data" : [
{
"version_value" : "12.0" ,
"version_affected" : "="
} ,
{
"version_value" : "12.1" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Financial Services Revenue Management and Billing Analytics" ,
"version" : {
"version_data" : [
{
"version_value" : "2.6" ,
"version_affected" : "="
} ,
{
"version_value" : "2.7" ,
"version_affected" : "="
} ,
{
"version_value" : "2.8" ,
"version_affected" : "="
}
]
}
}
]
} ,
2020-07-14 14:06:15 -07:00
"vendor_name" : "Oracle Corporation" ,
2020-04-14 13:46:18 -07:00
"product" : {
"product_data" : [
{
"product_name" : "Financial Services Revenue Management and Billing Analytics" ,
"version" : {
"version_data" : [
{
"version_value" : "2.6" ,
"version_affected" : "="
} ,
{
"version_value" : "2.7" ,
"version_affected" : "="
} ,
{
"version_value" : "2.8" ,
"version_affected" : "="
}
]
}
}
]
} ,
2020-07-14 13:34:15 -07:00
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Communications Network Integrity" ,
"version" : {
"version_data" : [
{
"version_value" : "7.3.2-7.3.6" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation" ,
"product" : {
"product_data" : [
{
"product_name" : "Financial Services Lending and Leasing" ,
"version" : {
"version_data" : [
{
"version_value" : "12.5.0" ,
"version_affected" : "="
} ,
{
"version_value" : "14.1.0-14.2.0" ,
"version_affected" : "="
}
]
}
}
]
} ,
"vendor_name" : "Oracle Corporation"
2019-10-16 18:01:37 +00:00
}
2019-10-15 13:20:38 -07:00
]
2019-10-16 18:01:37 +00:00
}
} ,
2020-01-15 20:01:19 +00:00
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
2019-03-18 05:37:40 +00:00
{
2020-01-15 20:01:19 +00:00
"lang" : "eng" ,
"value" : "Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
2019-03-18 05:37:40 +00:00
}
2019-10-16 18:01:37 +00:00
]
} ,
2020-02-07 10:22:41 -08:00
"impact" : {
"cvss" : {
"baseScore" : "9.8" ,
"vectorString" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"version" : "3.0"
}
} ,
2020-01-15 20:01:19 +00:00
"problemtype" : {
"problemtype_data" : [
2019-10-15 13:20:38 -07:00
{
2020-01-15 20:01:19 +00:00
"description" : [
2019-10-16 18:01:37 +00:00
{
2020-01-15 20:01:19 +00:00
"lang" : "eng" ,
"value" : "Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF."
2019-10-16 18:01:37 +00:00
}
]
2019-10-15 13:20:38 -07:00
}
2019-10-16 18:01:37 +00:00
]
} ,
2020-01-15 20:01:19 +00:00
"references" : {
"reference_data" : [
2019-10-15 13:20:38 -07:00
{
2020-01-15 20:01:19 +00:00
"url" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html" ,
"refsource" : "MISC" ,
"name" : "http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
2019-12-19 22:01:00 +00:00
} ,
{
2020-01-15 17:01:42 +00:00
"refsource" : "MISC" ,
"name" : "https://www.zerodayinitiative.com/advisories/ZDI-19-1024/" ,
"url" : "https://www.zerodayinitiative.com/advisories/ZDI-19-1024/"
2019-12-19 22:01:00 +00:00
} ,
{
2020-01-15 17:01:42 +00:00
"url" : "https://www.oracle.com/security-alerts/cpujan2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpujan2020.html"
2020-01-14 15:46:23 -08:00
} ,
2020-04-14 13:46:18 -07:00
{
2020-04-15 14:01:56 +00:00
"url" : "https://www.oracle.com/security-alerts/cpuapr2020.html" ,
"refsource" : "MISC" ,
"name" : "https://www.oracle.com/security-alerts/cpuapr2020.html"
2020-07-14 13:34:15 -07:00
} ,
{
"url" : "https://www.oracle.com/security-alerts/cpujul2020.html"
2020-01-15 20:01:19 +00:00
}
2019-10-16 18:01:37 +00:00
]
}
2020-07-14 14:06:15 -07:00
}