CVE-2019-2904 Details
Description
Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and ADF. Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper and ADF. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 15, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oracle application testing suite | 12.5.0.3 13.1.0.1 13.2.0.1 13.3.0.1 |
CPE
Remediation
| |
| oracle banking enterprise collections | 2.7.0 2.8.0 |
CPE
Remediation
| |
| oracle banking enterprise originations | 2.7.0 2.8.0 |
CPE
Remediation
| |
| oracle banking enterprise product manufacturing | 2.7.0 2.8.0 |
CPE
Remediation
| |
| oracle banking platform | 2.4.0 2.4.1 2.5.0 2.6.0 2.6.1 2.6.2 2.7.0 2.7.1 2.9.0 |
CPE
Remediation
| |
| oracle business process management suite | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle clinical | 5.2 |
CPE
Remediation
| |
| oracle communications diameter signaling router | >= 8.0.0.0, <= 8.4.0.5 |
CPE
Remediation
| |
| oracle communications network integrity | >= 7.3.2, <= 7.3.6 |
CPE
Remediation
| |
| oracle communications service broker | 6.0 6.1 |
CPE
Remediation
| |
| oracle communications services gatekeeper | 6.0 6.1 |
CPE
Remediation
| |
| oracle enterprise repository | 11.1.1.7.0 |
CPE
Remediation
| |
| oracle financial services lending and leasing | >= 14.1.0, <= 14.2.0 12.5.0 |
CPE
Remediation
| |
| oracle financial services revenue management and billing analytics | 2.6 2.7 2.8 |
CPE
Remediation
| |
| oracle flexcube private banking | 12.0.0 12.1.0 |
CPE
Remediation
| |
| oracle health sciences data management workbench | 2.4 2.5 |
CPE
Remediation
| |
| oracle hyperion planning | 11.1.2.4 |
CPE
Remediation
| |
| oracle rapid planning | 12.1.3 |
CPE
Remediation
| |
| oracle retail assortment planning | 15.0.3.0 16.0.3.0 |
CPE
Remediation
| |
| oracle retail clearance optimization engine | 13.4 14.0.3 14.0.5 |
CPE
Remediation
| |
| oracle retail markdown optimization | 13.4 |
CPE
Remediation
| |
| oracle retail sales audit | 15.0.3 16.0.2 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 18, 2021 | Reanalysis | [email protected] |
| May 5, 2021 | Modified Analysis | [email protected] |
| Apr 22, 2021 | CVE Modified | [email protected] |
| Oct 21, 2020 | CVE Modified | [email protected] |
| Jul 15, 2020 | CVE Modified | [email protected] |
| Apr 15, 2020 | CVE Modified | [email protected] |
| Feb 7, 2020 | CVE Modified | [email protected] |
| Jan 15, 2020 | CVE Modified | [email protected] |
| Dec 19, 2019 | CVE Modified | [email protected] |
| Oct 18, 2019 | Initial Analysis | [email protected] |