CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2015-3456 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilites (CPUJUL2015)

2016年11月22日 1582点热度 0人点赞 0条评论

漏洞类别:Local

漏洞等级:

漏洞信息

Oracle's PeopleSoft applications are designed to address the most complex business requirements.

Multiple vulnerabilities were reported in Oracle PeopleSoft Products.
- Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: PeopleSoft-VM). Very difficult to exploit vulnerability requiring logon to Operating System. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.
- Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security). Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTPS. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.
- Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some PeopleSoft Enterprise PeopleTools accessible data.

Affected Version
PeopleSoft Enterprise PeopleTools prior to 8.53.24
PeopleSoft Enterprise PeopleTools prior to 8.54.13

漏洞危害

Successful exploitation allows attacker to compromise the system.

解决方案

Newer version is available to download. For more information about this product or to check for new releases, go to the Oracle PeopleSoft Products.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

cpujul2015

0day

标签: 暂无
最后更新:2016年11月24日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me