CVE-2019-2907 is a vulnerability in the Oracle Web Services product of Oracle Fusion Middleware, specifically affecting the SOAP with Attachments API for Java in version 12.2.1.3.0. This easily exploitable flaw allows an unauthenticated attacker to compromise Oracle Web Services via HTTP network access. Successful attacks can lead to unauthorized read, update, insert, or delete access to a subset of the affected product's data, with potential impact on additional products. The vulnerability carries a CVSS 3.0 Base Score of 7.2 (High), indicating significant confidentiality and integrity impacts. Its attack vector is network-based, requires no user interaction, and has low attack complexity, making it a critical concern. Despite its severity, there is no evidence of active exploitation, nor are there known public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:web_services:12.2.1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.