E-mail Notification Vulnerability in Oracle PeopleSoft Enterprise HCM Candidate Gateway
CVE-2021-2404
6.5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 July 2021
Summary
A vulnerability exists in Oracle's PeopleSoft Enterprise HCM Candidate Gateway, impacting the e-mail notification component. An unauthorized attacker with network access can exploit this weakness to gain unauthorized access to sensitive data. Successful exploitation allows the attacker to update, insert, or delete data without proper authorization, as well as read certain confidential information, thereby compromising the integrity and confidentiality of the data managed by the Candidate Gateway. The vulnerability highlights the need for improved security measures to safeguard against unauthorized interactions with the system.
Affected Version(s)
PeopleSoft Enterprise HCM Candidate Gateway 9.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved