CVE-2020-14806: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14806?
CVE-2020-14806 is considered to have a high severity level due to its easily exploitable nature.
How do I fix CVE-2020-14806?
To remediate CVE-2020-14806, users should apply the latest patches provided by Oracle for affected versions 8.56, 8.57, and 8.58.
Who is affected by CVE-2020-14806?
Organizations using Oracle PeopleSoft Enterprise PeopleTools versions 8.56, 8.57, or 8.58 are affected by CVE-2020-14806.
What type of vulnerability is CVE-2020-14806?
CVE-2020-14806 is classified as an unauthenticated remote code execution vulnerability.
Can CVE-2020-14806 be exploited remotely?
Yes, CVE-2020-14806 can be exploited remotely by an unauthenticated attacker with network access via HTTP.