First published: Tue Apr 23 2019(Updated: )
Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager component of Oracle PeopleSoft Products (subcomponent: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Talent Acquisition Manager accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Talent Acquisition Manager accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager | =9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2590 is classified as a high severity vulnerability due to its ease of exploitation.
To mitigate CVE-2019-2590, apply the latest security patches provided by Oracle for the affected version 9.2.
Organizations using Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager version 9.2 are at risk from CVE-2019-2590.
An unauthenticated attacker could exploit CVE-2019-2590 to gain unauthorized access to sensitive information.
Currently, Oracle has not provided specific workarounds for CVE-2019-2590 aside from applying available patches.