CVE-2018-3165: High severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: SQR). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3165?
CVE-2018-3165 is classified as a high severity vulnerability due to the potential for high privileged attackers to exploit it.
How do I fix CVE-2018-3165?
To mitigate CVE-2018-3165, upgrade to a patched version of Oracle PeopleSoft Enterprise PeopleTools beyond 8.56.
Who is affected by CVE-2018-3165?
CVE-2018-3165 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.55 and 8.56.
What type of vulnerability is CVE-2018-3165?
CVE-2018-3165 is an easily exploitable vulnerability that allows attackers with network access to compromise the PeopleSoft Enterprise system.
Can CVE-2018-3165 be exploited remotely?
Yes, CVE-2018-3165 can be exploited remotely via HTTP by a high privileged attacker.