CVE-2018-2593: High severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2593?
CVE-2018-2593 is rated as a critical vulnerability due to its potential for unauthorized access by unauthenticated attackers.
How do I fix CVE-2018-2593?
To remediate CVE-2018-2593, you should apply the latest patches provided by Oracle for affected PeopleSoft Enterprise versions.
Which versions of PeopleSoft are affected by CVE-2018-2593?
CVE-2018-2593 impacts Oracle PeopleSoft Enterprise PeopleTools versions 8.54, 8.55, and 8.56.
Can CVE-2018-2593 be exploited remotely?
Yes, CVE-2018-2593 can be exploited remotely by unauthenticated attackers with network access via HTTP.
What component of Oracle PeopleSoft does CVE-2018-2593 affect?
CVE-2018-2593 affects the PeopleSoft Enterprise PeopleTools component, specifically the PIA Core Technology subcomponent.