Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-3870 | First vendor Publication | 2007-07-18 |
Vendor | Cve | Last vendor Modification | 2017-07-29 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.6 | Attack Range | Local |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple unspecified vulnerabilities in the Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 Bundle 11 allow local users to have unknown impact via unknown vectors, aka (1) PSE06 and (2) PSE07. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3870 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
39968 | Oracle PeopleSoft Human Capital Management Unspecified Local Information Disc... PeopleSoft Human Capital Management (HCM) contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when a manager with access to the "View Employee Personal Info" component creates a URL pointing to the component while specifying an alternate employee ID, which will disclose the addresses of employees who may not report to them resulting in a loss of confidentiality. |
39967 | Oracle PeopleSoft Human Capital Management Unspecified Local Issue PeopleSoft Human Capital Management contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when a manager with access to Absence Management components alters a URL substituting another employee ID, which will disclose and allow the editing of the absence information of an employee who may not report to the manager, resulting in a loss of confidentiality and integrity. |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2021-05-04 12:06:08 |
|
2021-04-22 01:06:41 |
|
2020-05-23 00:20:09 |
|
2017-07-29 12:02:24 |
|
2016-04-26 16:23:24 |
|
2013-05-11 10:31:59 |
|