MEDIUM · 6.4

CVE-2008-4000

Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality and integrity ...

Vulnerability Description

Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the Oracle October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue allows bypass of the lockout mechanism using brute force guessing of credentials and a response discrepancy information leak when the password is correct.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
JdedwardsEnterpriseone8.48.18
OracleJd Edwards Enterpriseone8.49.14
OraclePeoplesoft Enterprise8.48.18
OraclePeoplesoft Peopletools8.49.14

References

FAQ

What is CVE-2008-4000?

CVE-2008-4000 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality and integrity ...

How severe is CVE-2008-4000?

CVE-2008-4000 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-4000?

Check the references section above for vendor advisories and patch information. Affected products include: Jdedwards Enterpriseone, Oracle Jd Edwards Enterpriseone, Oracle Peoplesoft Enterprise, Oracle Peoplesoft Peopletools.