Vulnerability in Oracle PeopleSoft eProcurement Component
CVE-2017-10134
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 8 August 2017
What is CVE-2017-10134?
A vulnerability exists in the eProcurement subcomponent of Oracle PeopleSoft's Enterprise FSCM, affecting version 9.2. This vulnerability allows an attacker with low privileges to gain unauthorized access to sensitive data through HTTP requests. While exploiting this vulnerability requires human interaction from a user other than the attacker, it can lead to unauthorized updates, inserts, or deletions of accessible data within the PeopleSoft system. Moreover, successful exploitation may result in unauthorized read access to certain subsets of customer data, which may have far-reaching implications beyond the immediate scope of PeopleSoft Enterprise FSCM.
Affected Version(s)
PeopleSoft Enterprise SCM eProcurement 9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved