CVE-2020-2906: Medium severity oracle peoplesoft enterprise supply chain management services procurement vulnerability
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Supplier Change). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2906?
The severity of CVE-2020-2906 is medium with a severity value of 6.5.
What is the affected version of Oracle PeopleSoft in CVE-2020-2906?
The affected version of Oracle PeopleSoft in CVE-2020-2906 is 9.2.
How can a low privileged attacker exploit CVE-2020-2906?
A low privileged attacker with network access via HTTP can exploit CVE-2020-2906.
What is the component affected by CVE-2020-2906 in Oracle PeopleSoft?
The component affected by CVE-2020-2906 in Oracle PeopleSoft is Supplier Change.
How can I mitigate the vulnerability in CVE-2020-2906?
To mitigate the vulnerability in CVE-2020-2906, apply the necessary patches provided by Oracle.