CVE-2017-3548 is a vulnerability in the Integration Broker subcomponent of Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to a subset of PeopleSoft data and cause a partial denial of service. With a CVSS 3.0 score of 6.5 (Medium), it primarily impacts confidentiality and availability. While not actively exploited in the wild or on the CISA KEV catalog, public exploit code exists, including a Metasploit module, and it has a high FAUCET Risk Score of 98/100, indicating significant potential for exploitation. Despite this, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.54CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:* | ||
8.55CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.