{"id":"CVE-2017-3548","description":"Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily \"exploitable\" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).","cvssScore":6.5,"cvssVersion":"3.0","cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cvssMetrics":[{"version":"3.0","score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":6.4,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-611"],"resolved":"MITIGATED-BY-RASP","published":"2017-04-24","lastModified":"2026-06-17","affectedProducts":[{"vendor":"oracle","product":"peoplesoft enterprise peopletools","version":"8.54"},{"vendor":"oracle","product":"peoplesoft enterprise peopletools","version":"8.55"}],"totalAffectedProducts":1,"references":[{"url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html","source":"secalert_us@oracle.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/97880","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1038301","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://erpscan.io/advisories/erpscan-17-020-xxe-via-doctype-peoplesoft/","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"https://www.exploit-db.com/exploits/41925/","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]}],"reasoning":{"decidingSource":"manual-classification","decidingReason":"A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR XXE rule with uri parameter, xxe.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR XXE rule with uri parameter, xxe.","decisive":true}]},"relatedFiles":{"classificationFile":"data/classifications/CVE-2017-3548.md","classificationContent":"LS0tCmN2ZUlkOiBDVkUtMjAxNy0zNTQ4CnJlc29sdXRpb246IE1JVElHQVRFRC1CWS1TRUNVUkUtUlVMRQphcm1yUnVsZTogW3h4ZV0KLS0tCgojIyBDb21tZW50cwoKKipSdWxlIE5hbWUqKjogWFhFIHJ1bGUgd2l0aCB1cmkgcGFyYW1ldGVyLCB4eGUKCi0gWFhFIFZJQSBET0NUWVBFIGluIFBlb3BsZVNvZnQuIEV4cGxvaXQgd2Fsa3Rocm91Z2g6IGh0dHBzOi8vd3d3LmV4cGxvaXQtZGIuY29tL2V4cGxvaXRzLzQxOTI1CgojIyBSdWxlIGV4YW1wbGUKCmBgYGFybXIKYXBwKCJYWEUgU0VDVVJJVFkgUE9MSUNZIik6CiAgICByZXF1aXJlcyh2ZXJzaW9uOiBBUk1SLzIuOCkKICAgIG1hcnNoYWwoIlhYRTpBTExPVyIpOgogICAgICAgIHh4ZSh1cmk6IFsiaHR0cDovL3N0cnV0cy5hcGFjaGUub3JnL2R0ZHMvc3RydXRzLTIuMy5kdGQiLAogICAgICAgICAgICAgICAgICAiaHR0cDovL3N0cnV0cy5hcGFjaGUub3JnL2R0ZHMvc3RydXRzLTIuNS5kdGQiLAogICAgICAgICAgICAgICAgICAiaHR0cDovL2phdmEuc3VuLmNvbS9kdGQvd2ViLWpzcHRhZ2xpYnJhcnlfMV8yLmR0ZCIsCiAgICAgICAgICAgICAgICAgICJodHRwOi8vamF2YS5zdW4uY29tL2oyZWUvZHRkcy93ZWItanNwdGFnbGlicmFyeV8xXzEuZHRkIl0pCiAgICAgICAgYWxsb3cobWVzc2FnZTogIkFuIGV4dGVybmFsIERURCBVUkkgaGFzIGJlZW4gYWxsb3dlZCIpCiAgICBlbmRtYXJzaGFsCmVuZGFwcApgYGAK","classificationCreated":"2026-09-14T16:51:25+01:00"},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update April 2017","releaseType":"CPU","quarter":"2017-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2017.html","products":[{"product":"Oracle PeopleSoft Products","component":"Integration Broker","affectedVersions":"8.54, 8.55"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"],"armrRules":["xxe"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** HTTP, INTEGRATION BROKER, NO AUTH REMOTE EXPLOIT\n\n**Products:** ORACLE PEOPLESOFT PRODUCTS, PEOPLESOFT ENTERPRISE PEOPLETOOLS","exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/43114","title":"Oracle PeopleSoft Enterprise PeopleTools \u003c 8.55 - Remote Code Execution Via Blind XML External Entity","date":"2017-05-17"},{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/41925","title":"Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE","date":"2017-04-25"}],"signals":{"hasPOC":true,"pocCount":2,"pocSources":["exploit-db"],"firstPOCDate":"2017-04-25"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.50837,"percentile":0.98861},"ssvc":{"available":true,"exploitation":"none","automatable":"yes","technicalImpact":"partial"},"lastActivity":"2026-09-14T20:56:18+02:00"}