Exploitable Vulnerability in PeopleSoft Enterprise CS Campus Community by Oracle
CVE-2021-2159
3.5LOW
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 22 April 2021
Summary
A vulnerability exists in the PeopleSoft Enterprise CS Campus Community product where low privileged attackers with network access via HTTP can exploit this issue. The vulnerability requires human interaction from an individual other than the attacker to succeed, potentially allowing unauthorized read access to specific data within the system, thus posing risks to data confidentiality. Users operating version 9.2 of this product should take measures to mitigate potential risks.
Affected Version(s)
PeopleSoft Enterprise CS Campus Community 9.2
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved