CVE-2020-2775: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2775?
CVE-2020-2775 is classified as a critical vulnerability due to its potential for unauthenticated access and exploitation.
How do I fix CVE-2020-2775?
To mitigate CVE-2020-2775, users should apply the latest security patches provided by Oracle for PeopleSoft Enterprise PeopleTools.
Which versions of Oracle PeopleSoft are affected by CVE-2020-2775?
CVE-2020-2775 affects Oracle PeopleSoft Enterprise PeopleTools versions 8.56, 8.57, and 8.58.
Who can exploit CVE-2020-2775?
CVE-2020-2775 can be exploited by an unauthenticated attacker with network access via HTTP.
What component of Oracle PeopleSoft does CVE-2020-2775 impact?
CVE-2020-2775 impacts the Portal component of Oracle PeopleSoft Enterprise PeopleTools.