PT-2019-2014 · Oracle · Oracle Autovue 3D Professional Advanced

Published

2019-04-16

·

Updated

2020-08-24

·

CVE-2019-2575

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle AutoVue 3D Professional Advanced versions 21.0.0 through 21.0.1
Description The issue is related to inadequate access control in the Format Handling - 2D subcomponent of Oracle AutoVue 3D Professional Advanced, allowing an unauthenticated attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized read access to a subset of accessible data.
Recommendations For versions 21.0.0 and 21.0.1, consider restricting access to the Format Handling - 2D subcomponent until a patch is available. As a temporary workaround, limit HTTP access to Oracle AutoVue 3D Professional Advanced to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01707
CVE-2019-2575

Affected Products

Oracle Autovue 3D Professional Advanced