PT-2019-1948 · Oracle · Peoplesoft Enterprise Peopletools

Publicado

2019-04-16

·

Atualizado

2020-08-24

·

CVE-2019-2598

CVSS v2.0

9.4

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise PeopleTools versions 8.55 through 8.57
Description The issue is related to insufficient access controls in a subcomponent of PeopleSoft Enterprise PeopleTools, specifically the SQR component. This can be exploited by a remote attacker to gain unauthorized access to modify, add, or delete data using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data within PeopleSoft Enterprise PeopleTools.
Recommendations For versions 8.55 through 8.57, consider restricting access to the SQR subcomponent until a patch is available to prevent potential exploitation. Additionally, review and enforce strict access controls and privileges for all users interacting with PeopleSoft Enterprise PeopleTools to minimize the risk of unauthorized data modification or access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01617
CVE-2019-2598

Produtos afetados

Peoplesoft Enterprise Peopletools