Vulnerability in Oracle PeopleSoft Strategic Sourcing Affects Data Access
CVE-2018-2702
6.5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 January 2018
Summary
A vulnerability exists in the PeopleSoft Enterprise FSCM component, specifically within the Strategic Sourcing subcomponent of Oracle PeopleSoft Products version 9.2. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, potentially allowing them to gain unauthorized access to sensitive data. Successful exploitation may result in the attacker having complete access to all accessible data within the PeopleSoft Enterprise FSCM system, raising significant concerns for data confidentiality. Mitigation strategies should be implemented promptly to safeguard against possible malicious attacks.
Affected Version(s)
PeopleSoft Enterprise SCM Strategic Sourcing 9.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved