#VU39113 XML External Entity injection in PeopleSoft Enterprise PeopleTools - CVE-2017-3548

 

#VU39113 XML External Entity injection in PeopleSoft Enterprise PeopleTools - CVE-2017-3548

Published: April 24, 2017 / Updated: August 9, 2020


Vulnerability identifier: #VU39113
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2017-3548
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
PeopleSoft Enterprise PeopleTools
Software vendor:
Oracle

Description

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).


Remediation

Install update from vendor's website.

External links