CVE-2017-3547 is a vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55, specifically within the MultiChannel Framework subcomponent. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools, leading to unauthorized creation, deletion, or modification of critical data. While requiring user interaction, successful attacks can significantly impact data integrity across PeopleSoft products. With a CVSS 3.0 Base Score of 7.4 (High), this vulnerability has a high integrity impact but no known public exploits, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.54CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:* | ||
8.55CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.