CVE-2020-2912
Last modified
CVE-2020-2912 is a medium-severity vulnerability rated 5/10 on the CVSS scale. Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The supported version that is affected is 9.2. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Self-Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. While the vulnerability is in PeopleSoft Enterprise CS Campus Community, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.0 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Peoplesoft Enterprise Campus Software Campus Community | 9.2 |
References
- https://www.oracle.com/security-alerts/cpuapr2020.htmlVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2912?
How severe is CVE-2020-2912?
How do I fix CVE-2020-2912?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-29074scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls,…8.8
- CVE-2020-29075Acrobat Reader DC versions 2020.013.20066 (and earlier), 202…6.5
- CVE-2020-2908Vulnerability in the Oracle VM VirtualBox product of Oracle …8.2
- CVE-2020-2909Vulnerability in the Oracle VM VirtualBox product of Oracle …2.8
- CVE-2020-2910Vulnerability in the Oracle VM VirtualBox product of Oracle …6.5
- CVE-2020-2911Vulnerability in the Oracle VM VirtualBox product of Oracle …7.5
- CVE-2020-29127An issue was discovered on Fujitsu Eternus Storage DX200 S4 …9.8
- CVE-2020-29128petl before 1.68, in some configurations, allows resolution …9.8
- CVE-2020-29129ncsi.c in libslirp through 4.3.1 has a buffer over-read beca…4.3
- CVE-2020-2913Vulnerability in the Oracle VM VirtualBox product of Oracle …7
- CVE-2020-29130slirp.c in libslirp through 4.3.1 has a buffer over-read bec…4.3
- CVE-2020-29133jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded…6.1
Are you affected by CVE-2020-2912?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
