CVE-2017-10366
37Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 43%
from disclosure to weapon88 days
Published on NVDOct 19
1st PoC+88d
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected products
Oracle Corporation · PeopleSoft Enterprise PT PeopleToolspublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/43594unverifiedgithubgithub.com/blazeinfosec/CVE-2017-10366_peoplesoft★ 25cve_referencewww.exploit-db.com/exploits/43594/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.