Vulnerability in PeopleSoft Enterprise HCM Shared Components by Oracle
CVE-2021-2455
6.5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 July 2021
Summary
An improper access control vulnerability exists in Oracle's PeopleSoft Enterprise HCM Shared Components, specifically within the Person Search component. This vulnerability can be exploited by an attacker with elevated privileges, allowing them to gain unauthorized access via HTTP. As a result, they may manipulate critical data, including the ability to create, delete, or modify sensitive information accessible within the PeopleSoft Enterprise HCM environment. This can lead to severe implications regarding data integrity and confidentiality.
Affected Version(s)
PeopleSoft Enterprise HCM Shared Components 9.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved