XML External Entity injection in PeopleSoft Enterprise PeopleTools - CVE-2017-3548

 

XML External Entity injection in PeopleSoft Enterprise PeopleTools - CVE-2017-3548

Published: April 24, 2017 / Updated: August 9, 2020


Vulnerability identifier: #VU39113
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2017-3548
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vendor: Oracle
Affected software:
PeopleSoft Enterprise PeopleTools

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).


How to mitigate CVE-2017-3548

Install update from vendor's website.

Sources