First published: Wed Oct 17 2018(Updated: )
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Query). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Peoplesoft Enterprise Campus Software Campus Community | =8.55 | |
Oracle Peoplesoft Enterprise Campus Software Campus Community | =8.56 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3192 is rated as a high-severity vulnerability that allows a privileged attacker to compromise Oracle PeopleSoft applications.
To fix CVE-2018-3192, you should apply the latest patches provided by Oracle for the affected versions 8.55 and 8.56.
CVE-2018-3192 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.55 and 8.56.
CVE-2018-3192 allows an attacker with high privileges and network access to exploit the vulnerability through HTTP.
CVE-2018-3192 was disclosed in October 2018 through Oracle's security advisory.