CVE-2019-2709 is an easily exploitable vulnerability in Oracle Transportation Management (versions 6.3.7, 6.4.2, and 6.4.3) that allows an unauthenticated attacker to compromise the system via HTTP. While requiring user interaction, successful attacks can lead to unauthorized modification or deletion of some data, and unauthorized read access to a subset of data within Oracle Transportation Management. This vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating potential impacts to confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.3.7CPE matchmatch criteria | cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:* | ||
6.4.2CPE matchmatch criteria | cpe:2.3:a:oracle:transportation_management:6.4.2:*:*:*:*:*:*:* | ||
6.4.3CPE matchmatch criteria | cpe:2.3:a:oracle:transportation_management:6.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.