CVE-2018-3198: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3198?
CVE-2018-3198 is considered a high severity vulnerability that allows unauthenticated attackers to compromise Oracle PeopleSoft systems.
How do I fix CVE-2018-3198?
To fix CVE-2018-3198, apply the latest security patches provided by Oracle for PeopleSoft version 8.55, 8.56, or 8.57.
Who is affected by CVE-2018-3198?
Organizations using Oracle PeopleSoft Enterprise PeopleTools versions 8.55, 8.56, and 8.57 are affected by CVE-2018-3198.
What type of vulnerability is CVE-2018-3198?
CVE-2018-3198 is an easily exploitable web vulnerability that can be accessed via HTTP.
Can CVE-2018-3198 be exploited remotely?
Yes, CVE-2018-3198 can be exploited remotely by an unauthenticated attacker with network access.