Improper input validation in Oracle Enterprise Manager Ops Center - CVE-2019-5443
Published: June 5, 2020
Vulnerability identifier: #VU28648
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5443
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Networking (cURL) component in Enterprise Manager Ops Center. A local authenticated user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Enterprise Manager Ops Center
MySQL Server
Secured Component Verification (SCV)
MySQL Server
Secured Component Verification (SCV)
How to mitigate CVE-2019-5443
Install updates from vendor's website.
MySQL Server - addressed in versions 5.7.28, 8.0.18
Secured Component Verification (SCV) - update to 1.92.0
Secured Component Verification (SCV) - update to 1.92.0