PT-2019-1948 · Oracle · Peoplesoft Enterprise Peopletools
Published
2019-04-16
·
Updated
2020-08-24
·
CVE-2019-2598
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
PeopleSoft Enterprise PeopleTools versions 8.55 through 8.57
Description
The issue is related to insufficient access controls in a subcomponent of PeopleSoft Enterprise PeopleTools, specifically the SQR component. This can be exploited by a remote attacker to gain unauthorized access to modify, add, or delete data using the HTTP protocol. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data within PeopleSoft Enterprise PeopleTools.
Recommendations
For versions 8.55 through 8.57, consider restricting access to the SQR subcomponent until a patch is available to prevent potential exploitation. Additionally, review and enforce strict access controls and privileges for all users interacting with PeopleSoft Enterprise PeopleTools to minimize the risk of unauthorized data modification or access.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peoplesoft Enterprise Peopletools