CVE-2018-3068 is a medium-severity vulnerability affecting Oracle PeopleSoft Enterprise HCM Human Resources version 9.2, specifically within the Compensation subcomponent. This easily exploitable flaw allows an unauthenticated attacker to gain unauthorized read and limited write access to sensitive data through network access via HTTP, requiring user interaction. While not actively exploited in the wild and lacking public exploit code, its potential to impact additional products beyond HCM Human Resources warrants attention. The CVSS 3.0 Base Score is 6.1, indicating confidentiality and integrity impacts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.