CVE-2014-2446Missing Authorization in Oracle Peoplesoft Products

Severity
4.0MEDIUMNVD
GHSA9.1
EPSS
0.2%
top 61.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16
Latest updateMay 24

Description

Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via vectors related to QAS.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

NVDoracle/peoplesoft_products8.52, 8.53+1

🔴Vulnerability Details

3
GHSA
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins2022-05-24
GHSA
GHSA-7x5c-764v-q5v3: Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 82022-05-17
CVEList
CVE-2014-2446: Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 82014-04-16
CVE-2014-2446 — Missing Authorization in Oracle | cvebase