Vulnerability in Oracle PeopleSoft Products: Security Flaw in Enterprise HCM
CVE-2017-10304

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

An exploitable security vulnerability exists in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products. This flaw allows low-privileged attackers with network access via HTTP to manipulate data within the system. While the vulnerability resides in PeopleSoft Enterprise HCM, its successful exploitation can lead to unauthorized alterations, such as updates, insertions, or deletions of sensitive data. The attack requires human interaction, which indicates that the system's defenses could be bypassed through social engineering techniques. Additionally, the breach may result in unauthorized access to confidential information across additional, interconnected PeopleSoft products, heightening the risk of data exposure.

Affected Version(s)

PeopleSoft Enterprise HCM Human Resources 9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.