CVE-2019-2904
published 2019-10-16CVE-2019-2904: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.26%
96.2th percentile
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | banking_enterprise_collections | — | — |
| oracle | banking_enterprise_collections | — | — |
| oracle | banking_enterprise_originations | — | — |
| oracle | banking_enterprise_originations | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | business_process_management_suite | — | — |
| oracle | clinical | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0.0 – 8.4.0.5 | — |
| oracle | communications_network_integrity | 7.3.2 – 7.3.6 | — |
| oracle | communications_service_broker | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·Affected versions are 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.3.0 of Oracle JDeveloper and ADF (ADF Faces component). The vulnerability is exploitable over HTTP with no authentication required. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: User interface (Application Development Framework) — CVE-2019-2904
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2019-2904 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: User interface (Application Development Framework) — CVE-2019-2904
Oracle Oracle Supply Chain Risk Matrix: User interface (Application Development Framework) vulnerability
CVE: CVE-2019-2904
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Application Development Framework) — CVE-2019-2904
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2019-2904 [CRITICAL] Oracle Oracle Communications Risk Matrix: Platform (Application Development Framework) — CVE-2019-2904
Oracle Oracle Communications Risk Matrix: Platform (Application Development Framework) vulnerability
CVE: CVE-2019-2904
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: User Interface (Application Development Framework) — CVE-2019-2904
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2019-2904 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: User Interface (Application Development Framework) — CVE-2019-2904
Oracle Oracle Communications Applications Risk Matrix: User Interface (Application Development Framework) vulnerability
CVE: CVE-2019-2904
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Application Development Framework) — CVE-2019-2904
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2019-2904 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Admin Console (Application Development Framework) — CVE-2019-2904
Oracle Oracle Communications Applications Risk Matrix: Admin Console (Application Development Framework) vulnerability
CVE: CVE-2019-2904
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Application Development Framework) — CVE-2019-2904
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2019-2904 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Application Development Framework) — CVE-2019-2904
Oracle Oracle Enterprise Manager Risk Matrix: Load Testing for Web Apps (Application Development Framework) vulnerability
CVE: CVE-2019-2904
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
GHSA
GHSA-c5wp-xqq4-5j7g: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces)
ghsa_unreviewed·2022-05-24
CVE-2019-2904 [HIGH] GHSA-c5wp-xqq4-5j7g: Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces)
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
No detection rules found.
No public exploits indexed.
Tenable
Oracle January 2020 Critical Patch Update Contains 255 CVEs
blogs_tenable·2020-01-15
Oracle January 2020 Critical Patch Update Contains 255 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle Critical Patch Update for October Contains 180 Fixes
blogs_tenable·2019-10-16
Oracle Critical Patch Update for October Contains 180 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-18928 cyrus-imapd: privilege escalation in HTTP request
bugzilla·2019-11-21·CVSS 9.8
CVE-2019-18928 [CRITICAL] CVE-2019-18928 cyrus-imapd: privilege escalation in HTTP request
CVE-2019-18928 cyrus-imapd: privilege escalation in HTTP request
A vulnerability was found in Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Reference:
https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.14.html
https://www.cyrusimap.org/imap/download/release-notes/3.0/x/3.0.12.html
Discussion:
Created cyrus-imapd tracking bugs for this issue:
Affects: fedora-all [bug 1775179]
---
External References:
https://github.com/cyrusimap/cyrus-imapd/issues/2904
---
Statement:
If HTTP is enabled (e.g. RSS, CalDAV), cyrus-imapd does not properly authenticate a HTTP request coming through a connection
http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-1024/http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.zerodayinitiative.com/advisories/ZDI-19-1024/
2019-10-16
Published