CVE-2019-2483
published 2024-12-24CVE-2019-2483: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2…
PriorityP345high8.2CVSS 3.0
AVNACLPRNUIRSCCHILAN
EPSS
0.40%
31.7th percentile
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle | istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
| oracle_corporation | oracle_istore | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10199 keycloak: CSRF check missing in My Resources functionality in the Account Console
bugzilla·2019-07-11·CVSS 8.8
CVE-2019-10199 [HIGH] CVE-2019-10199 keycloak: CSRF check missing in My Resources functionality in the Account Console
CVE-2019-10199 keycloak: CSRF check missing in My Resources functionality in the Account Console
A vulnerability was found in keycloak. A CSRF attack can be performed in My Resources functionality in the Account Console. The attacker can trick the user to perform operations by using social engineering or any other mean that can result in a request to Keycloak from an untrusted domain.
References:
https://issues.jboss.org/browse/KEYCLOAK-10775
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3.3 zip
Via RHSA-2019:2483 https://access.redhat.com/errata/RHSA-2019:2483
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-10199
---
This iss
Bugzilla
CVE-2019-10201 keycloak: SAML broker does not check existence of signature on document allowing any user impersonation
bugzilla·2019-07-10·CVSS 8.1
CVE-2019-10201 [HIGH] CVE-2019-10201 keycloak: SAML broker does not check existence of signature on document allowing any user impersonation
CVE-2019-10201 keycloak: SAML broker does not check existence of signature on document allowing any user impersonation
If an attacker modifies the SAML Response and removes the Sections, the message is still accepted and the message can be modified, allowing the attacker to impersonate any user on the keycloak protected systems by modifying assertations.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-10786
Discussion:
Mitigation:
Administrator can prevent this issue for POST binding by requiring signed assertions.
---
Red Hat Mobile Application Platform does not make use of SAML identity brokering.
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.3.3 zip
Via RHSA-2019:2483 https://access.redhat.com/errata/RHSA-2019:2483
---
This
2024-12-24
Published