Vulnerability in Oracle PeopleSoft Enterprise PeopleTools SQR Component
CVE-2021-35609
6.5MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 October 2021
Summary
This vulnerability affects the SQR component of Oracle PeopleSoft Enterprise PeopleTools, allowing low-privileged attackers with network access via HTTP to gain unauthorized access. The flaw can lead to exposure of sensitive information, undermining the integrity and confidentiality of critical data within the affected PeopleTools versions.
Affected Version(s)
PeopleSoft Enterprise PT PeopleTools 8.57
PeopleSoft Enterprise PT PeopleTools 8.58
PeopleSoft Enterprise PT PeopleTools 8.59
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved