CVE-2014-2495: Low severity oracle peoplesoft products vulnerability
Published Jul 17, 2014
·Updated
Unspecified vulnerability in the PeopleSoft Enterprise SCM Purchasing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Purchasing.
Affected Software
2 affected components
Oracle PeopleSoft Products=9.1
Oracle PeopleSoft Products=9.2
Event History
Jul 17, 2014
CVE Published
via MITRE·02:36 AM
Data Sourced
via MITRE·02:36 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2495?
The severity of CVE-2014-2495 is currently unknown due to the unspecified nature of the vulnerability.
2
Who is affected by CVE-2014-2495?
CVE-2014-2495 affects remote authenticated users of Oracle PeopleSoft Products versions 9.1 and 9.2.
3
What impact does CVE-2014-2495 have on confidentiality?
CVE-2014-2495 allows remote authenticated users to potentially compromise confidentiality within the Purchasing component.
4
How do I fix CVE-2014-2495?
To fix CVE-2014-2495, apply the latest security patches provided by Oracle for PeopleSoft Products.
5
Is CVE-2014-2495 a local or remote vulnerability?
CVE-2014-2495 is considered a remote vulnerability as it involves remote authenticated users.