← back
CVE-2017-3548

CVE-2017-3548

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 51%
from disclosure to weapon1 days
Published on NVDApr 24
1st PoC+1d
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.