{"api_version":"1","generated_at":"2026-07-23T06:44:49+00:00","cve":"CVE-2013-5909","urls":{"html":"https://cve.report/CVE-2013-5909","api":"https://cve.report/api/cve/CVE-2013-5909.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-5909","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-5909"},"summary":{"title":"CVE-2013-5909","description":"Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Org and Workforce Dev.","state":"PUBLISHED","assigner":"oracle","published_at":"2014-01-15 16:08:06","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Oracle Critical Patch Update - January 2014","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029623","name":"http://www.securitytracker.com/id/1029623","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Oracle PeopleSoft Products Bugs Let Remote Users Partially Access and Modify Data and Partially Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/64855","name":"http://www.securityfocus.com/bid/64855","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Oracle PeopleSoft Enterprise HRMS CVE-2013-5909 Remote Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/56477","name":"http://secunia.com/advisories/56477","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA56477 - Oracle PeopleSoft Enterprise HRMS Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/102035","name":"http://osvdb.org/102035","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/64758","name":"http://www.securityfocus.com/bid/64758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-5909","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5909","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"5909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"peoplesoft_products","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"5909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"peoplesoft_products","cpe6":"9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"5909","cve":"CVE-2013-5909","epss":"0.003930000","percentile":"0.602780000","score_date":"2026-05-02","updated_at":"2026-05-03 00:00:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T17:29:41.181Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"64855","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/64855"},{"name":"102035","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/102035"},{"name":"56477","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56477"},{"name":"1029623","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029623"},{"name":"64758","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/64758"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Org and Workforce Dev."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-01-30T23:57:02.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"64855","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/64855"},{"name":"102035","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/102035"},{"name":"56477","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56477"},{"name":"1029623","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029623"},{"name":"64758","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/64758"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2013-5909","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Org and Workforce Dev."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"64855","refsource":"BID","url":"http://www.securityfocus.com/bid/64855"},{"name":"102035","refsource":"OSVDB","url":"http://osvdb.org/102035"},{"name":"56477","refsource":"SECUNIA","url":"http://secunia.com/advisories/56477"},{"name":"1029623","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029623"},{"name":"64758","refsource":"BID","url":"http://www.securityfocus.com/bid/64758"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2013-5909","datePublished":"2014-01-15T01:33:00.000Z","dateReserved":"2013-09-18T00:00:00.000Z","dateUpdated":"2024-08-06T17:29:41.181Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-01-15 16:08:06","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_products:9.1:*:*:*:*:*:*:*","matchCriteriaId":"90A75D6A-35E3-496B-AD93-0F7B2CA44BA6"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_products:9.2:*:*:*:*:*:*:*","matchCriteriaId":"DA527891-D956-4125-9067-3AE3FB0BD4DD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"5909","Ordinal":"1","Title":"CVE-2013-5909","CVE":"CVE-2013-5909","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"5909","Ordinal":"1","NoteData":"Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Org and Workforce Dev.","Type":"Description","Title":"CVE-2013-5909"},{"CveYear":"2013","CveId":"5909","Ordinal":"2","NoteData":"2014-01-14","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"5909","Ordinal":"3","NoteData":"2014-01-30","Type":"Other","Title":"Modified"}]}}}