Unauthorized Data Access Vulnerability in Oracle PeopleSoft's Campus Community Product
CVE-2020-2912

5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in Oracle PeopleSoft's Campus Community product that allows a low-privileged attacker with network access via HTTP to compromise the system. Specifically, this flaw permits unauthorized read access to sensitive data within the PeopleSoft Enterprise CS Campus Community. Although primarily impacting this product, the effects of the attack could extend to related systems. Organizations using version 9.2 need to be aware of the potential data exposure from this easily exploitable vulnerability.

Affected Version(s)

PeopleSoft Enterprise CS Campus Community 9.2

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.