PT-2004-3327 · Oracle · Peoplesoft Human Resources Management System

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2435

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: PeopleSoft Human Resources Management System (HRMS) version 7.0
Description: The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML. The attack vectors are unspecified debugging or utility scripts.
Recommendations: For PeopleSoft Human Resources Management System (HRMS) version 7.0, consider disabling HTML Access for web-enabled modules as a temporary workaround until a patch is available. Restrict access to debugging and utility scripts to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2435

Affected Products

Peoplesoft Human Resources Management System