CVE-2017-10257 is an easily exploitable vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products, specifically affecting version 9.1.0. An unauthenticated attacker can leverage network access via HTTP to compromise the system, requiring user interaction to succeed. Successful exploitation can lead to unauthorized modification or read access to a subset of the Interaction Hub's data. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating impacts to confidentiality and integrity. The attack vector is network-based with low attack complexity, but requires user interaction. While the vulnerability is in the Interaction Hub, successful attacks may significantly impact additional products. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, consistent with the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_prtl_interaction_hub:9.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.