CVE-2019-2433: High severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: XML Publisher). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2433?
CVE-2019-2433 has a high severity rating due to its potential for exploitation by privileged attackers.
How do I fix CVE-2019-2433?
To fix CVE-2019-2433, it is recommended to apply the latest patches provided by Oracle for versions 8.55, 8.56, and 8.57.
Who is affected by CVE-2019-2433?
CVE-2019-2433 affects users of Oracle PeopleSoft Enterprise PeopleTools versions 8.55, 8.56, and 8.57.
What type of attacks can CVE-2019-2433 enable?
CVE-2019-2433 can enable high privileged attackers to compromise the system through network access via HTTP.
Is CVE-2019-2433 easily exploitable?
Yes, CVE-2019-2433 is considered easily exploitable, making it a significant concern for security.