PT-2020-4846 · Oracle · Peoplesoft Enterprise Hcm Global Payroll Core
Ammarit Thongthua
+2
·
Published
2020-10-21
·
Updated
2020-10-26
·
CVE-2020-14778
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PeopleSoft Enterprise HCM Global Payroll Core version 9.2
Description:
The issue is related to insufficient input validation in the Security component of the PeopleSoft Enterprise HCM Global Payroll Core application. This can be exploited by a remote attacker to gain unauthorized access to protected information, modify, add, or delete data, or cause a denial of service. The vulnerability can be easily exploited by a low-privileged attacker with network access via HTTP, allowing them to compromise the PeopleSoft Enterprise HCM Global Payroll Core product. Successful attacks can result in unauthorized access to some data, including read access to a subset of data and the ability to cause a partial denial of service.
Recommendations:
For version 9.2, update the Security component to a version that includes the necessary input validation checks to prevent exploitation.
As a temporary workaround, consider restricting access to the Security component until a patch is available.
Avoid using the HTTP protocol to access the PeopleSoft Enterprise HCM Global Payroll Core product until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peoplesoft Enterprise Hcm Global Payroll Core