CVE-2014-2446 — Missing Authorization in Oracle Peoplesoft Products
Severity
4.0MEDIUMNVD
GHSA9.1
EPSS
0.2%
top 61.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 16
Latest updateMay 24
Description
Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via vectors related to QAS.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9
Affected Packages1 packages
🔴Vulnerability Details
3GHSA▶
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins↗2022-05-24
GHSA▶
GHSA-7x5c-764v-q5v3: Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8↗2022-05-17
CVEList▶
CVE-2014-2446: Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8↗2014-04-16