Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN Expenses accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Metrics
Affected Vendors & Products
References
History
Wed, 06 Nov 2024 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo |
Thu, 31 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 |
Thu, 17 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Oracle PeopleSoft: From CVEorg collector | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 15 Oct 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Expenses. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FIN Expenses accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). | |
First Time appeared |
Oracle
Oracle peoplesoft Enterprise Fin Expenses |
|
CPEs | cpe:2.3:a:oracle:peoplesoft_enterprise_fin_expenses:9.2:*:*:*:*:*:*:* | |
Vendors & Products |
Oracle
Oracle peoplesoft Enterprise Fin Expenses |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: oracle
Published: 2024-10-15T19:52:51.089Z
Updated: 2024-10-31T14:25:43.483Z
Reserved: 2023-12-07T22:28:10.700Z
Link: CVE-2024-21249
Vulnrichment
Updated: 2024-10-17T13:18:28.194Z
NVD
Status : Analyzed
Published: 2024-10-15T20:15:14.880
Modified: 2024-11-06T22:53:50.587
Link: CVE-2024-21249
Redhat