PT-2021-3027 · Oracle · Peoplesoft Enterprise Cs Campus Community

Published

2021-04-20

·

Updated

2021-04-23

·

CVE-2021-2159

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PeopleSoft Enterprise CS Campus Community version 9.2
Description The issue is related to insufficient input validation in the Frameworks component of the Oracle PeopleSoft Enterprise CS Campus Community application. This can be exploited by a remote attacker to gain unauthorized access to protected information via the HTTP protocol. The attack requires human interaction from someone other than the attacker and can result in unauthorized read access to a subset of accessible data.
Recommendations For version 9.2, update the Frameworks component to a version that includes the necessary security patches to address the insufficient input validation issue. As a temporary workaround, consider restricting access to the Frameworks component to minimize the risk of exploitation. Additionally, ensure that all inputs are thoroughly validated to prevent potential attacks.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02633
CVE-2021-2159

Affected Products

Peoplesoft Enterprise Cs Campus Community