CVE-2020-14847: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14847?
CVE-2020-14847 is classified as a high-severity vulnerability.
How do I fix CVE-2020-14847?
To mitigate CVE-2020-14847, update to a patched version of Oracle PeopleSoft Enterprise PeopleTools.
Which versions of PeopleSoft are affected by CVE-2020-14847?
CVE-2020-14847 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.56, 8.57, and 8.58.
Can an attacker exploit CVE-2020-14847 remotely?
Yes, CVE-2020-14847 can be exploited by a high privileged attacker with network access via HTTP.
What component of Oracle PeopleSoft does CVE-2020-14847 affect?
CVE-2020-14847 affects the Query component of the Oracle PeopleSoft Enterprise PeopleTools.