CVE-2019-2572
Last modified
CVE-2019-2572 is a vulnerability of currently unknown severity. Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.9.0. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle SOA Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Soa Suite | 11.1.1.9.0 |
References
- http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-2572?
How severe is CVE-2019-2572?
How do I fix CVE-2019-2572?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-25713MyT-PM 1.5.1 contains an SQL injection vulnerability that al…8.1
- CVE-2019-25714Seeyon OA A8 contains an unauthenticated arbitrary file writ…9.3
- CVE-2019-25716Dräger Infinity Delta, Delta XL, and Kappa patient monitors …7.5
- CVE-2019-25717Dräger Infinity Delta, Delta XL, and Kappa patient monitors …5.3
- CVE-2019-25718Dräger Infinity Explorer C700 contains a privilege escalatio…7.8
- CVE-2019-25719Dräger Infinity Acute Care System and Standalone Infinity M5…8.8
- CVE-2019-25720Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000,…7.1
- CVE-2019-25721Dräger Infinity M300 patient worn monitors with software ver…7.1
- CVE-2019-25722Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000,…7.6
- CVE-2019-25723Dräger Perseus A500 software versions 2.00 through 2.02 cont…6.3
- CVE-2019-25724Dräger Infinity M300 patient worn monitors with software ver…7.1
- CVE-2019-25726All in One Video Downloader 1.2 contains an SQL injection vu…8.8
Are you affected by CVE-2019-2572?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
