Unauthorized Access Vulnerability in Oracle PeopleSoft HCM
CVE-2020-2561
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 January 2020
Summary
An unauthorized access vulnerability exists in the Oracle PeopleSoft Enterprise HCM Human Resources product, specifically within the Company Directory / Org Chart Viewer component. This vulnerability allows low privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized read access to sensitive data. Affected users of PeopleSoft Enterprise HCM 9.2 should be aware of this risk, as it can expose confidential information and compromise data integrity.
Affected Version(s)
PeopleSoft Enterprise HCM Human Resources 9.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved