CVE-2017-3315
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vulnerability in the PeopleSoft Enterprise HCM ePerformance component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM ePerformance. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise HCM ePerformance accessible data. CVSS v3.0 Base Score 4.3 (Confidentiality impacts).
Vulnerabilidad en el componente PeopleSoft Enterprise HCM ePerformance de Oracle PeopleSoft Products (subcomponente: Security). La versión compatible que está afectada es 9.2. Vulnerabilidad fácilmente explotable permite a un atacante poco privilegiado con acceso a la red a través de HTTP, comprometer PeopleSoft Enterprise HCM ePerformance. Ataques exitosos de esta vulnerabilidad pueden resultar en acceso de lectura no autorizado a un subconjunto de datos accesibles de HCM ePerformance. CVSS v3.0 Base Score 4.3 (Impactos de confidencialidad).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2016-12-06 CVE Reserved
- 2017-01-27 CVE Published
- 2023-03-08 EPSS Updated
- 2024-10-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95510 | Third Party Advisory | |
http://www.securitytracker.com/id/1037634 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html | 2017-02-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Peoplesoft Enterprise Human Capital Management Eperformance Search vendor "Oracle" for product "Peoplesoft Enterprise Human Capital Management Eperformance" | 9.2 Search vendor "Oracle" for product "Peoplesoft Enterprise Human Capital Management Eperformance" and version "9.2" | - |
Affected
|