Integration and Interfaces Vulnerability in Oracle PeopleSoft Enterprise CS Campus Community
CVE-2021-2421
6.5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 July 2021
Summary
An integration and interfaces vulnerability exists in Oracle PeopleSoft Enterprise CS Campus Community that permits low privileged attackers with network access via HTTP to exploit the system. This vulnerability can lead to unauthorized access to sensitive data, potentially compromising the integrity of accessible information. Affected versions include 9.0 and 9.2, which may allow attackers to manipulate or exfiltrate data without proper authentication.
Affected Version(s)
PeopleSoft Enterprise CS Campus Community 9.0
PeopleSoft Enterprise CS Campus Community 9.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved