First published: Wed Jul 18 2018(Updated: )
Vulnerability in the PeopleSoft HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft HRMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft HRMS accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Human Resource Management Software | =9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3072 is considered to be easily exploitable, allowing unauthenticated attackers to compromise PeopleSoft HRMS.
To fix CVE-2018-3072, apply the recommended security patches provided by Oracle for PeopleSoft HRMS version 9.2.
CVE-2018-3072 specifically affects Oracle PeopleSoft HRMS version 9.2.
CVE-2018-3072 impacts the Candidate Gateway subcomponent of the PeopleSoft HRMS.
Yes, CVE-2018-3072 can be exploited remotely by an unauthenticated attacker with network access via HTTP.