Vulnerability in Oracle PeopleSoft SCM eProcurement Affects Multiple Versions
CVE-2017-10368
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
An exploitable security flaw exists in the eProcurement component of Oracle PeopleSoft Enterprise SCM. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the system. Although successful exploitation requires human interaction from a third party, it poses significant risks including unauthorized modifications, deletions, or even reading of sensitive data within the PeopleSoft environment. As these vulnerabilities affect core functionalities, they may extend their impact to other integrated applications.
Affected Version(s)
PeopleSoft Enterprise SCM eProcurement 9.1.00
PeopleSoft Enterprise SCM eProcurement 9.2.00
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved