Vulnerability CVE-2019-2721


Published: 2019-04-23

Description:
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Type:

CWE-20

(Improper Input Validation)

Vendor: Oracle
Product: Vm virtualbox 
Version:
6.0.4
6.0.2
6.0.0
5.2.8
5.2.6
5.2.4
5.2.26
5.2.24
5.2.22
5.2.20
5.2.2
5.2.18
5.2.16
5.2.14
5.2.12
5.2.10
5.2.0
5.1.8
5.1.6
5.1.4
5.1.38
5.1.36
5.1.34
5.1.32
5.1.30
5.1.28
5.1.26
5.1.24
5.1.22
5.1.20
5.1.2
5.1.18
5.1.16
5.1.14
5.1.12
5.1.10
5.1.0
5.0.8
5.0.6
5.0.40
5.0.4
5.0.38
5.0.36
5.0.34
5.0.32
5.0.30
5.0.28
5.0.26
5.0.24
5.0.22
5.0.20
5.0.2
5.0.18
5.0.16
5.0.14
5.0.13
5.0.12
5.0.10
5.0.0
4.3.8
4.3.6
4.3.4
4.3.38
4.3.36
4.3.35
4.3.34
4.3.32
4.3.30
4.3.29
4.3.28
4.3.26
4.3.24
4.3.22
4.3.2
4.3.18
4.3.16
4.3.14
4.3.12
4.3.10
4.3.0
4.2.8
4.2.6
4.2.4
4.2.36
4.2.34
4.2.32
4.2.31
4.2.30
4.2.28
4.2.26
4.2.24
4.2.22
4.2.20
4.2.2
4.2.18
4.2.16
4.2.14
4.2.12
4.2.10
4.2.0
See more versions on NVD

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.exploit-db.com/exploits/46747/

Related CVE
CVE-2019-2726
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent: Services Integration). The supported version that is affected is 12.3.3. Difficult to exploit vulnerability allows low privileged ...
CVE-2019-2725
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ...
CVE-2019-2723
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2722
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2720
Vulnerability in the Oracle Data Integrator component of Oracle Fusion Middleware (subcomponent: ODI Tools). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows low privileged attacker with ne...
CVE-2019-2719
Vulnerability in the Oracle Knowledge component of Oracle Siebel CRM (subcomponent: Web Applications (InfoCenter)). Supported versions that are affected are 8.5.1.0 - 8.5.1.7, 8.6.0 and 8.6.1. Easily exploitable vulnerability allows unauthenticated a...
CVE-2019-2713
Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access vi...
CVE-2019-2712
Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 11.2.0.3 and 11.3.1. Easily exploitable vulnerability allows unauthenticated attacker wi...

Copyright 2019, cxsecurity.com

 

Back to Top