CVE-2018-3192: High severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3192?
CVE-2018-3192 is rated as a high-severity vulnerability that allows a privileged attacker to compromise Oracle PeopleSoft applications.
How do I fix CVE-2018-3192?
To fix CVE-2018-3192, you should apply the latest patches provided by Oracle for the affected versions 8.55 and 8.56.
Who is affected by CVE-2018-3192?
CVE-2018-3192 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.55 and 8.56.
What is the type of attack associated with CVE-2018-3192?
CVE-2018-3192 allows an attacker with high privileges and network access to exploit the vulnerability through HTTP.
When was CVE-2018-3192 disclosed?
CVE-2018-3192 was disclosed in October 2018 through Oracle's security advisory.