Vulnerability in PeopleSoft Enterprise PRTL Interaction Hub of Oracle
CVE-2017-10247
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 8 August 2017
What is CVE-2017-10247?
An improperly managed access control vulnerability exists in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products. This flaw allows an unauthenticated remote attacker to exploit the system with HTTP access, potentially gaining unauthorized update, insert, or delete access to sensitive data. Additionally, attacks may require human interaction from a user other than the attacker, amplifying the risk to user data. While the vulnerability targets the PRTL Interaction Hub specifically, the impact could extend to other connected Oracle PeopleSoft Products, leading to serious integrity and confidentiality concerns.
Affected Version(s)
PeopleSoft Enterprise PRTL Interaction Hub 9.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved