PT-2021-3027 · Oracle · Peoplesoft Enterprise Cs Campus Community
Published
2021-04-20
·
Updated
2021-04-23
·
CVE-2021-2159
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PeopleSoft Enterprise CS Campus Community version 9.2
Description
The issue is related to insufficient input validation in the Frameworks component of the Oracle PeopleSoft Enterprise CS Campus Community application. This can be exploited by a remote attacker to gain unauthorized access to protected information via the HTTP protocol. The attack requires human interaction from someone other than the attacker and can result in unauthorized read access to a subset of accessible data.
Recommendations
For version 9.2, update the Frameworks component to a version that includes the necessary security patches to address the insufficient input validation issue. As a temporary workaround, consider restricting access to the Frameworks component to minimize the risk of exploitation. Additionally, ensure that all inputs are thoroughly validated to prevent potential attacks.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peoplesoft Enterprise Cs Campus Community