CVE-2017-3548: XEE
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle PeopleSoft Enterprise PeopleTools (Integration Broker)to a version that resolves this vulnerability.Fixed in 8.54 - Upgrade
Upgrade
Oracle PeopleSoft Enterprise PeopleTools (Integration Broker)to a version that resolves this vulnerability.Fixed in 8.55
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3548?
CVE-2017-3548 is considered an easily exploitable vulnerability allowing unauthorized access.
How do I fix CVE-2017-3548?
To remediate CVE-2017-3548, upgrade to a non-affected version of Oracle PeopleSoft Enterprise PeopleTools.
What components are affected by CVE-2017-3548?
CVE-2017-3548 affects the Integration Broker component of the PeopleSoft Enterprise PeopleTools.
Who is impacted by CVE-2017-3548?
Organizations using Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55 are impacted by CVE-2017-3548.
Can CVE-2017-3548 be exploited remotely?
Yes, CVE-2017-3548 can be exploited by an unauthenticated attacker with network access via HTTP.