CVE-2017-3502
MEDIUMOracle PeopleSoft Products <9.2 - Unauthenticated RCE
Title source: llmDescription
Vulnerability in the PeopleSoft Enterprise FIN Receivables component of Oracle PeopleSoft Products (subcomponent: Receivables). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Receivables. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Receivables accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Scores
CVSS v3
5.3
EPSS
0.0061
EPSS Percentile
69.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
Status
published
Affected Products (2)
oracle/peoplesoft_enterprise_fin_receivables
Oracle Corporation/PeopleSoft Enterprise FIN Receivables
< 9.2
Timeline
Published
Apr 24, 2017
Tracked Since
Feb 18, 2026