CVE-2017-10287: Infoleak
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10287?
CVE-2017-10287 has been classified as a high severity vulnerability.
How do I fix CVE-2017-10287?
To fix CVE-2017-10287, apply the latest security patches and updates provided by Oracle for PeopleSoft Enterprise 9.2.
Who is affected by CVE-2017-10287?
CVE-2017-10287 affects users of the PeopleSoft Enterprise FSCM component, specifically version 9.2.
What exploit vectors are available for CVE-2017-10287?
CVE-2017-10287 is easily exploitable with low privileged access via HTTP.
What are the potential impacts of exploiting CVE-2017-10287?
Exploiting CVE-2017-10287 may allow an attacker to compromise the PeopleSoft Enterprise environment.