CVE-2019-3015: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3015?
CVE-2019-3015 is considered an easily exploitable vulnerability that poses a significant risk to affected PeopleSoft Enterprise products.
What versions are affected by CVE-2019-3015?
CVE-2019-3015 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.56 and 8.57.
How do I fix CVE-2019-3015?
To mitigate CVE-2019-3015, it is recommended to apply the latest security patches provided by Oracle.
Can CVE-2019-3015 be exploited remotely?
Yes, CVE-2019-3015 can be exploited by low privileged attackers with network access via HTTP.
What component of Oracle PeopleSoft is impacted by CVE-2019-3015?
CVE-2019-3015 impacts the Integration Broker component of the PeopleSoft Enterprise PeopleTools product.