CVE-2008-4000
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the Oracle October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue allows bypass of the lockout mechanism using brute force guessing of credentials and a response discrepancy information leak when the password is correct.
Vulnerabilidad no especificada en el componente PeopleTools en Oracle PeopleSoft Enterprise y JD Edwards EnterpriseOne v8.48.18 y v8.49.14 permite a atacantes remotos afectar a la confidencialidad e integridad a través de vectores desconocidos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-09 CVE Reserved
- 2008-10-14 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuoct2008-100299.html | X_refsource_confirm | |
http://www.securityfocus.com/archive/1/497543/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1021055 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/2825 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45902 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/32291 | 2018-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jdedwards Search vendor "Jdedwards" | Enterpriseone Search vendor "Jdedwards" for product "Enterpriseone" | 8.48.18 Search vendor "Jdedwards" for product "Enterpriseone" and version "8.48.18" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jd Edwards Enterpriseone Search vendor "Oracle" for product "Jd Edwards Enterpriseone" | 8.49.14 Search vendor "Oracle" for product "Jd Edwards Enterpriseone" and version "8.49.14" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Search vendor "Oracle" for product "Peoplesoft Enterprise" | 8.48.18 Search vendor "Oracle" for product "Peoplesoft Enterprise" and version "8.48.18" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Peoplesoft Peopletools Search vendor "Oracle" for product "Peoplesoft Peopletools" | 8.49.14 Search vendor "Oracle" for product "Peoplesoft Peopletools" and version "8.49.14" | - |
Affected
|