CVE-2019-2439 is a vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.55, 8.56, and 8.57, specifically affecting the Portal subcomponent. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require user interaction and can lead to unauthorized read, update, insert, or delete access to a subset of PeopleSoft data, potentially impacting other products. The vulnerability has a CVSS 3.0 Base Score of 6.1 (Medium), indicating a moderate risk. The attack vector is network-based (AV:N), with low attack complexity (AC:L), and requires user interaction (UI:R). While the impact on confidentiality and integrity is low (C:L, I:L), the scope is changed (S:C), meaning the vulnerability in one component can affect others. There is currently no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.55CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.55:*:*:*:*:*:*:* | ||
8.56CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* | ||
8.57CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.