Vulnerability in Oracle PeopleSoft Enterprise PeopleTools SQR Component
CVE-2021-35609

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

This vulnerability affects the SQR component of Oracle PeopleSoft Enterprise PeopleTools, allowing low-privileged attackers with network access via HTTP to gain unauthorized access. The flaw can lead to exposure of sensitive information, undermining the integrity and confidentiality of critical data within the affected PeopleTools versions.

Affected Version(s)

PeopleSoft Enterprise PT PeopleTools 8.57

PeopleSoft Enterprise PT PeopleTools 8.58

PeopleSoft Enterprise PT PeopleTools 8.59

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.