CVE-2024-21264

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 15, 2024

Summary

CVE-2024-21264 is a vulnerability affecting the PeopleSoft Enterprise CC Common Application Objects product, specifically within the Activity Guide Composer component of Oracle PeopleSoft version 9.2. This flaw allows low-privileged attackers with network access via HTTP to gain unauthorized access, potentially leading to unauthorized updates, inserts, or deletions of sensitive data. The vulnerability has a CVSS 3.1 Base Score of 5.4, indicating medium severity with impacts on confidentiality and integrity but no availability impact. To remediate this issue, organizations are advised to apply security patches provided in Oracle's October 2024 Critical Patch Update. Failure to address this vulnerability could compromise sensitive data and system integrity within affected environments.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share