PT-2020-2593 · Oracle · Peoplesoft Enterprise Hcm Absence Management

Published

2020-04-14

·

Updated

2020-04-16

·

CVE-2020-2947

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise HCM Absence Management version 9.2
Description The issue is related to insufficient access controls in the Absence Management component of Oracle PeopleSoft Enterprise HCM Absence Management. This can be exploited by a remote attacker to gain unauthorized access to protected information using the HTTP protocol. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data.
Recommendations For version 9.2, consider restricting access to the Absence Management component until a patch is available. As a temporary workaround, limit the use of HTTP protocol for sensitive operations to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02627
CVE-2020-2947

Affected Products

Peoplesoft Enterprise Hcm Absence Management