PT-2017-15938 · Oracle · Peoplesoft Enterprise Fin Receivables

Published

2017-04-24

·

Updated

2019-10-03

·

CVE-2017-3502

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise FIN Receivables version 9.2
Description The issue affects the PeopleSoft Enterprise FIN Receivables component, allowing an unauthenticated attacker with network access via HTTP to compromise it. Successful attacks can result in unauthorized access to update, insert, or delete some accessible data.
Recommendations For version 9.2, update to a version that includes a fix for this issue, as the current version allows for easy exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-3502

Affected Products

Peoplesoft Enterprise Fin Receivables