Vulnerability in Financial Sanctions Component of Oracle PeopleSoft
CVE-2021-2044
6.5MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2021
What is CVE-2021-2044?
A vulnerability exists in the Financial Sanctions component of Oracle PeopleSoft Enterprise FIN Payables, specifically affecting version 9.2. This flaw can be exploited by low-privileged attackers with network access via HTTP, enabling them to gain unauthorized access to sensitive data. Successful exploitation may lead to the exposure of critical information or even complete control over the accessible data within the PeopleSoft application, highlighting significant security risks for organizations using this platform.
Affected Version(s)
PeopleSoft Enterprise FIN Payables 9.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved