CVE-2019-2896
Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations). Supported versions that are affected are 7.1.0, 15.0.0, 16.0.0, 17.0.0, and 18.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MICROS Relate CRM Software. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MICROS Relate CRM Software accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.37%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-2896",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2019-2896",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-01T16:15:50.598162Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "secalert_us@oracle.com",
"affectedData": [
{
"vendor": "Oracle Corporation",
"product": "MICROS Relate CRM Software",
"versions": [
{
"status": "affected",
"version": "7.1.0"
},
{
"status": "affected",
"version": "15.0.0"
},
{
"status": "affected",
"version": "16.0.0"
},
{
"status": "affected",
"version": "17.0.0"
},
{
"status": "affected",
"version": "18.0.0"
}
]
}
]
}
],
"published": "2019-10-16T18:15:27.043",
"references": [
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in the MICROS Relate CRM Software product of Oracle Retail Applications (component: Internal Operations). Supported versions that are affected are 7.1.0, 15.0.0, 16.0.0, 17.0.0, and 18.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MICROS Relate CRM Software. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MICROS Relate CRM Software accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el producto MICROS Relate CRM Software de Oracle Retail Applications (componente: Internal Operations). Las versiones compatibles que están afectadas son 7.1.0, 15.0.0, 16.0.0, 17.0.0 y 18.0.0. Una vulnerabilidad difícil de explotar permite a un atacante no autenticado con acceso a la red por medio de HTTP comprometer a MICROS Relate CRM Software. Los ataques con éxito de esta vulnerabilidad pueden resultar en un acceso no autorizado a datos críticos o un acceso total a todos los datos accesibles del software MICROS Relate CRM. CVSS 3.0 Puntuación Base 5.9 (Impactos de la Confidencialidad). Vector CVSS: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)."
}
],
"lastModified": "2026-06-17T02:34:47.640",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:micros_relate_customer_relationship_management_software:7.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98331529-0C6F-4255-A828-65ABE0C7BDA3"
},
{
"criteria": "cpe:2.3:a:oracle:micros_relate_customer_relationship_management_software:15.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "213FDDE1-08A1-46FD-AACF-C309822B4915"
},
{
"criteria": "cpe:2.3:a:oracle:micros_relate_customer_relationship_management_software:16.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0781C757-E9B5-4DBF-81EA-990911D4FBD3"
},
{
"criteria": "cpe:2.3:a:oracle:micros_relate_customer_relationship_management_software:17.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD8C90C1-0F8B-4DC2-9B8C-AE2A7DCA4678"
},
{
"criteria": "cpe:2.3:a:oracle:micros_relate_customer_relationship_management_software:18.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15A26736-FB34-4BBA-A781-9B554437BFDC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert_us@oracle.com"
}