Unauthorized Access Vulnerability in PeopleSoft Enterprise PRTL Interaction Hub by Oracle
CVE-2017-10338
8.2HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
A vulnerability exists in Oracle's PeopleSoft Enterprise PRTL Interaction Hub that allows unauthenticated attackers to exploit the system through network access via HTTP. This flaw, primarily affecting version 9.1.00, could lead to unauthorized access to critical data, enabling attackers to execute unauthorized updates, inserts, or deletions. The exploitation of this vulnerability not only jeopardizes the integrity of the PeopleSoft data but also poses risks to connected products, as successful attacks necessitate human interaction from an unsuspecting user.
Affected Version(s)
PeopleSoft Enterprise PRTL Interaction Hub 9.1.00
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved