peter bassill · operator
$ cve CVE-2017-3546 JSON

CVE-2017-3546 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 9.6% (pctl 95)

Patch early

A public exploit exists.

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS9.64% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploityes
Published2017-04-24
Last modified2026-06-17

Affected (1)

VendorProduct
oraclepeoplesoft enterprise peopletools

Public exploits

SourceTitleDate
exploit-dbOracle PeopleSoft - Server-Side Request Forgery2017-05-19

References

→ the Explorer  ·  watch your stack  ·  NVD