Security Features in PeopleSoft Enterprise PeopleTools - CVE-2016-8329

 

Security Features in PeopleSoft Enterprise PeopleTools - CVE-2016-8329

Published: January 28, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39790
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-8329
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Oracle
Affected software:
PeopleSoft Enterprise PeopleTools

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Mobile Application Platform). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS v3.0 Base Score 6.1 (Confidentiality and Integrity impacts).


How to mitigate CVE-2016-8329

Install update from vendor's website.

Sources