PT-2017-15970 · Oracle · Peoplesoft Enterprise Peopletools

Published

2017-04-24

·

Updated

2019-10-03

·

CVE-2017-3536

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55
Description The issue allows a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized update, insert, or delete access to some of PeopleSoft Enterprise PeopleTools accessible data, as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.
Recommendations For versions 8.54 and 8.55, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-3536

Affected Products

Peoplesoft Enterprise Peopletools