Lucene search

K
cveOracleCVE-2019-2700
HistoryApr 23, 2019 - 7:32 p.m.

CVE-2019-2700

2019-04-2319:32:56
oracle
web.nvd.nist.gov
29
cve-2019-2700
oracle
peoplesoft
enterprise elm
vulnerability
compromise
http
cvss 3.0.

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

3.8

Confidence

High

EPSS

0.001

Percentile

22.7%

Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).

Affected configurations

Nvd
Vulners
Node
oraclepeoplesoft_enterprise_learning_managementMatch9.2
VendorProductVersionCPE
oraclepeoplesoft_enterprise_learning_management9.2cpe:2.3:a:oracle:peoplesoft_enterprise_learning_management:9.2:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "PeopleSoft Enterprise ELM Enterprise Learning Management",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "9.2"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

AI Score

3.8

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVE-2019-2700