Vulnerability in PeopleSoft Enterprise HCM Component of Oracle PeopleSoft Products
CVE-2017-10306
4.6MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 October 2017
What is CVE-2017-10306?
An access control vulnerability exists in the PeopleSoft Enterprise HCM component of Oracle PeopleSoft Products that allows a low privileged attacker with network access via HTTP to compromise the system. Successfully exploiting this vulnerability requires human interaction from a third party other than the attacker. It can lead to unauthorized update, insert, or delete access to some data within PeopleSoft Enterprise HCM, as well as unauthorized reading of a subset of accessible data. This can compromise both confidentiality and integrity within the affected system.
Affected Version(s)
PeopleSoft Enterprise HCM Human Resources 9.2