CVE-2019-2453 is a critical vulnerability in the Oracle Performance Management component of Oracle E-Business Suite versions 12.1.1, 12.1.2, and 12.1.3. This easily exploitable flaw allows an unauthenticated attacker to gain network access via HTTP, leading to unauthorized creation, modification, or deletion of critical data, as well as unauthorized access to all accessible data within Oracle Performance Management. With a CVSS 3.0 Base Score of 9.1 (Critical), it poses significant confidentiality and integrity risks. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:e-business_suite:12.1.1:*:*:*:*:*:*:* | ||
12.1.2CPE matchmatch criteria | cpe:2.3:a:oracle:e-business_suite:12.1.2:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.