CVE-2018-2951 is an easily exploitable vulnerability affecting Oracle PeopleSoft Enterprise PeopleTools versions 8.55 and 8.56, specifically within the Configuration Manager subcomponent. This unauthenticated flaw allows an attacker with logon access to the infrastructure to gain complete unauthorized access to all PeopleSoft Enterprise PeopleTools accessible data, resulting in a high confidentiality impact. With a CVSS 3.0 score of 6.2 (Medium), the vulnerability has a low attack complexity and requires local access. There is currently no known public exploit code (Metasploit, Nuclei, ExploitDB), and it shows minimal community discussion or media coverage, indicating it is not actively exploited or widely discussed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.55CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* | ||
8.56CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.