First published: Wed Oct 17 2018(Updated: )
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: SQR). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Peoplesoft Enterprise Campus Software Campus Community | =8.55 | |
Oracle Peoplesoft Enterprise Campus Software Campus Community | =8.56 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3165 is classified as a high severity vulnerability due to the potential for high privileged attackers to exploit it.
To mitigate CVE-2018-3165, upgrade to a patched version of Oracle PeopleSoft Enterprise PeopleTools beyond 8.56.
CVE-2018-3165 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.55 and 8.56.
CVE-2018-3165 is an easily exploitable vulnerability that allows attackers with network access to compromise the PeopleSoft Enterprise system.
Yes, CVE-2018-3165 can be exploited remotely via HTTP by a high privileged attacker.