PT-2020-2576 · Oracle · Peoplesoft Enterprise Peopletools
Tarun Sehgal
·
Published
2020-04-14
·
Updated
2020-04-16
·
CVE-2020-2782
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
PeopleSoft Enterprise PeopleTools versions 8.56 through 8.58
Description
The issue is related to insufficient access controls in the Query component of Oracle PeopleSoft Enterprise PeopleTools. It can be exploited by a remote attacker to cause a denial of service or gain unauthorized access to protected information via the HTTP protocol. Successful attacks may require human interaction and can significantly impact additional products, resulting in unauthorized access to data, including update, insert, or delete access, as well as read access to a subset of data. The vulnerability can also lead to a partial denial of service.
Recommendations
For versions 8.56 through 8.58, consider restricting access to the Query component until a patch is available to prevent unauthorized access and denial of service attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peoplesoft Enterprise Peopletools