PT-2019-1948 · Oracle · Peoplesoft Enterprise Peopletools
Publicado
2019-04-16
·
Atualizado
2020-08-24
·
CVE-2019-2598
CVSS v2.0
9.4
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
PeopleSoft Enterprise PeopleTools versions 8.55 through 8.57
Description
The issue is related to insufficient access controls in a subcomponent of PeopleSoft Enterprise PeopleTools, specifically the SQR component. This can be exploited by a remote attacker to gain unauthorized access to modify, add, or delete data using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data within PeopleSoft Enterprise PeopleTools.
Recommendations
For versions 8.55 through 8.57, consider restricting access to the SQR subcomponent until a patch is available to prevent potential exploitation. Additionally, review and enforce strict access controls and privileges for all users interacting with PeopleSoft Enterprise PeopleTools to minimize the risk of unauthorized data modification or access.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Peoplesoft Enterprise Peopletools