CVE-2026-35273

v celém archivu

zrušit filtry CZ · EN/orig

CVE-2026-35273

KEV ✓ EPSS 0.95 náprava do 15. 6. 2026

Hodnocení závažnosti

9.8 CVSS 3.1 oracle CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

1 karet z 4 položek

1

ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.

KEV ✓ EPSS 0.95 CVSS 9.8 CVE-2026-35273 Oracle Google Microsoft školství US 2 zdrojů

Zero Day Initiative · Mandiant / Google TI