Input validation error in PeopleSoft Enterprise PeopleTools - CVE-2013-3759

 

Input validation error in PeopleSoft Enterprise PeopleTools - CVE-2013-3759

Published: July 17, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42709
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2013-3759
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Oracle
Affected software:
PeopleSoft Enterprise PeopleTools

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Search Functionality.


How to mitigate CVE-2013-3759

Install update from vendor's website.

Sources