PT-2019-1948 · Oracle · Peoplesoft Enterprise Peopletools

Published

2019-04-16

·

Updated

2020-08-24

·

CVE-2019-2598

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise PeopleTools versions 8.55 through 8.57
Description The issue is related to insufficient access controls in a subcomponent of PeopleSoft Enterprise PeopleTools, specifically the SQR component. This can be exploited by a remote attacker to gain unauthorized access to modify, add, or delete data using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data within PeopleSoft Enterprise PeopleTools.
Recommendations For versions 8.55 through 8.57, consider restricting access to the SQR subcomponent until a patch is available to prevent potential exploitation. Additionally, review and enforce strict access controls and privileges for all users interacting with PeopleSoft Enterprise PeopleTools to minimize the risk of unauthorized data modification or access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01617
CVE-2019-2598

Affected Products

Peoplesoft Enterprise Peopletools