PT-2018-2479 · Oracle · Peoplesoft Enterprise Peopletools+1

Published

2018-10-16

·

Updated

2019-10-03

·

CVE-2018-3262

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle PeopleSoft Products version 8.55 Oracle PeopleSoft Products version 8.56 Oracle PeopleSoft Products version 8.57
Description The issue is related to insufficient access control in the Stylesheet component of Oracle PeopleSoft Enterprise PeopleTools, allowing an unauthenticated attacker with network access via HTTP to compromise the system. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products. This can result in unauthorized update, insert, or delete access to some of the accessible data in PeopleSoft Enterprise PeopleTools.
Recommendations For version 8.55, update the Stylesheet component to address the insufficient access control issue. For version 8.56, update the Stylesheet component to address the insufficient access control issue. For version 8.57, update the Stylesheet component to address the insufficient access control issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00754
CVE-2018-3262

Affected Products

Oracle Peoplesoft Products
Peoplesoft Enterprise Peopletools