CVE-2021-2407: Medium severity oracle peopletools vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2407?
CVE-2021-2407 is classified as an easily exploitable vulnerability that allows unauthenticated attackers to compromise applications.
How do I fix CVE-2021-2407?
To fix CVE-2021-2407, users should apply the latest security patches provided by Oracle for supported versions.
Which versions of PeopleSoft are affected by CVE-2021-2407?
The affected versions of PeopleSoft Enterprise PeopleTools are 8.57, 8.58, and 8.59.
Can CVE-2021-2407 be exploited remotely?
Yes, CVE-2021-2407 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
What component of PeopleSoft does CVE-2021-2407 impact?
CVE-2021-2407 impacts the Portal component of the PeopleSoft Enterprise PeopleTools product.