Unauthorized Data Access Vulnerability in Oracle PeopleSoft's Campus Community Product
CVE-2020-2912
5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 April 2020
Summary
A vulnerability exists in Oracle PeopleSoft's Campus Community product that allows a low-privileged attacker with network access via HTTP to compromise the system. Specifically, this flaw permits unauthorized read access to sensitive data within the PeopleSoft Enterprise CS Campus Community. Although primarily impacting this product, the effects of the attack could extend to related systems. Organizations using version 9.2 need to be aware of the potential data exposure from this easily exploitable vulnerability.
Affected Version(s)
PeopleSoft Enterprise CS Campus Community 9.2
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved