Junglewise Threat Intelligence

CVE-2017-3315: Oracle PeopleSoft Enterprise HCM ePerformance information disclosure in Security

CVE-2017-3315 · Severity: medium · CVSS 4.3 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle's PeopleSoft ePerformance module, which is used by organizations to manage employee evaluations and performance reviews. A low-privileged user with network access can exploit this flaw to gain unauthorized access to sensitive performance-related data. While the attacker cannot modify or delete information, this could lead to the exposure of confidential employee records and internal HR data.

Technical details

This vulnerability is classified as an information disclosure (CWE-200) within the Security subcomponent of Oracle PeopleSoft Enterprise HCM ePerformance. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended access controls to read a subset of data managed by the ePerformance component. The vulnerability does not provide a mechanism for data modification or service disruption (Integrity and Availability impacts are none). Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise HCM ePerformance 9.2

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017 published.

References