Vulnerabilities > CVE-2017-3546 - Server-Side Request Forgery (SSRF) vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.54/8.55

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
oracle
CWE-918
exploit available

Summary

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

Vulnerable Configurations

Part Description Count
Application
Oracle
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionOracle PeopleSoft - Server-Side Request Forgery. CVE-2017-3546. Webapps exploit for Java platform. Tags: Server-Side Request Forgery
fileexploits/java/webapps/42034.txt
idEDB-ID:42034
last seen2017-05-19
modified2017-05-19
platformjava
port
published2017-05-19
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/42034/
titleOracle PeopleSoft - Server-Side Request Forgery
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/142244/ERPSCAN-17-022.txt
idPACKETSTORM:142244
last seen2017-04-20
published2017-04-20
reporterRoman Shalymov
sourcehttps://packetstormsecurity.com/files/142244/Oracle-PeopleSoft-ToolsRelease-ToolsReleaseDB-HCM-SSRF.html
titleOracle PeopleSoft ToolsRelease / ToolsReleaseDB / HCM SSRF