Vulnerability in Financial Sanctions Component of Oracle PeopleSoft
CVE-2021-2044

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
20 January 2021

What is CVE-2021-2044?

A vulnerability exists in the Financial Sanctions component of Oracle PeopleSoft Enterprise FIN Payables, specifically affecting version 9.2. This flaw can be exploited by low-privileged attackers with network access via HTTP, enabling them to gain unauthorized access to sensitive data. Successful exploitation may lead to the exposure of critical information or even complete control over the accessible data within the PeopleSoft application, highlighting significant security risks for organizations using this platform.

Affected Version(s)

PeopleSoft Enterprise FIN Payables 9.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-2044 : Vulnerability in Financial Sanctions Component of Oracle PeopleSoft