#VU88701 Improper input validation in PeopleSoft Enterprise HCM Benefits Administration


Published: 2024-04-17

Vulnerability identifier: #VU88701

Vulnerability risk: Low

CVSSv3.1: 5.3 [CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-21063

CWE-ID: CWE-20

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
PeopleSoft Enterprise HCM Benefits Administration
Web applications / CRM systems

Vendor: Oracle

Description

The vulnerability allows a local authenticated user to read, manipulate or delete data.

The vulnerability exists due to improper input validation within the Benefits Administration component in PeopleSoft Enterprise HCM Benefits Administration. A local authenticated user can exploit this vulnerability to read, manipulate or delete data.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

PeopleSoft Enterprise HCM Benefits Administration: 9.2


External links
http://www.oracle.com/security-alerts/cpuapr2024.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability