CVE-2018-2821 describes a vulnerability within the Rich Text Editor subcomponent of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.54, 8.55, and 8.56. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful exploitation, which requires user interaction, can lead to unauthorized modification or deletion of some data, as well as unauthorized read access to a subset of data. The vulnerability carries a CVSS 3.0 Base Score of 6.1 (Medium), indicating low confidentiality and integrity impacts. The attack vector is network-based with low attack complexity, but requires user interaction. While the vulnerability is in PeopleTools, successful attacks may significantly impact additional products. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.54CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.54:*:*:*:*:*:*:* | ||
8.55CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* | ||
8.56CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.