CVE-2017-3315
https://notcve.org/view.php?id=CVE-2017-3315
Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM ePerformance. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise HCM ePerformance accessible data. CVSS v3.0 Base Score 4.3 (Confidentiality impacts). • http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html http://www.securityfocus.com/bid/95510 http://www.securitytracker.com/id/1037634 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-3300 – Oracle PeopleSoft HCM 9.2 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2017-3300
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Multichannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. • http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html http://www.securityfocus.com/bid/95505 http://www.securitytracker.com/id/1037634 https://erpscan.io/advisories/erpscan-17-005-oracle-peoplesoft-xss-vulnerability • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-5529
https://notcve.org/view.php?id=CVE-2016-5529
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5530 and CVE-2016-8293. Vulnerabilidad no especificada en el componente PeopleSoft Enterprise PeopleTools en Oracle PeopleSoft Products 8.54 y 8.55 permite a atacantes remotos afectar la confidencialidad y la integridad a través de vectores relacionados con Integration Broker, una vulnerabilidad diferente a CVE-2016-5530 y CVE-2016-8293. • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html http://www.securityfocus.com/bid/93700 http://www.securitytracker.com/id/1037046 •
CVE-2016-8285
https://notcve.org/view.php?id=CVE-2016-8285
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. Vulnerabilidad no especificada en el componente PeopleSoft Enterprise HCM en Oracle PeopleSoft Products 9.2 permite a administradores remotos afectar la confidencialidad y la integridad a través de vectores relacionados con Candidate Gateway. • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html http://www.securityfocus.com/bid/93723 http://www.securitytracker.com/id/1037046 • CWE-284: Improper Access Control •
CVE-2016-8293
https://notcve.org/view.php?id=CVE-2016-8293
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-5530. Vulnerabilidad no especificada en el componente PeopleSoft Enterprise PeopleTools en Oracle PeopleSoft Products 8.54 y 8.55 permite a atacantes remotos afectar la confidencialidad y la integridad a través de vectores relacionados con Integration Broker, una vulnerabilidad diferente a CVE-2016-5529 y CVE-2016-5530. • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html http://www.securityfocus.com/bid/93726 http://www.securitytracker.com/id/1037046 • CWE-284: Improper Access Control •