Unauthorized Access Vulnerability in Oracle PeopleSoft Enterprise CS Campus Community
CVE-2021-35606
5.7MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 October 2021
Summary
The PeopleSoft Enterprise CS Campus Community product by Oracle is impacted by a vulnerability within its Notification Framework. This issue allows an attacker with low privileges, who has physical access to the communication segment of the hardware, to exploit the system. Successful exploitation can lead to unauthorized access to sensitive information or entirely to all data accessible within the PeopleSoft Enterprise CS Campus Community framework, raising significant security concerns for affected organizations.
Affected Version(s)
PeopleSoft Enterprise CS Campus Community 9.0
PeopleSoft Enterprise CS Campus Community 9.2
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved