CVE-2018-2772: High severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Rich Text Editor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2772?
CVE-2018-2772 is considered an easily exploitable vulnerability that could allow a low privileged attacker to compromise the affected system.
How do I fix CVE-2018-2772?
To fix CVE-2018-2772, users should apply the patches released by Oracle for PeopleTools versions 8.54, 8.55, and 8.56.
What components are affected by CVE-2018-2772?
CVE-2018-2772 affects the Rich Text Editor component of Oracle PeopleSoft Enterprise PeopleTools.
Who is affected by CVE-2018-2772?
Organizations using Oracle PeopleSoft versions 8.54, 8.55, or 8.56 are affected by CVE-2018-2772.
What type of attacks can CVE-2018-2772 lead to?
CVE-2018-2772 could potentially lead to unauthorized access to sensitive data or manipulation of system functionality.