Bug 2318934 (CVE-2024-21202) - CVE-2024-21202 PIA Core Technology: From CVEorg collector
Summary: CVE-2024-21202 PIA Core Technology: From CVEorg collector
Keywords:
Status: NEW
Alias: CVE-2024-21202
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-10-15 20:10 UTC by OSIDB Bzimport
Modified: 2025-12-18 04:59 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-10-15 20:10:12 UTC
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.59, 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Comment 1 Johnson Charless 2025-09-04 06:12:18 UTC
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent.

Comment 2 Johnson Charless 2025-09-04 06:14:19 UTC
Thanks for the update. Since this is marked as a minor change with no email notification, I suggest we document the CVE details internally and ensure related teams are aware through the security tracker to avoid missing visibility.
Regards:
Team https://talksocially.com/

Comment 3 henrryhilton36@gmail.com 2025-11-03 14:10:07 UTC
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent.
Regards 
Bitcodesolution

Comment 4 henrryhilton36@gmail.com 2025-11-07 13:41:19 UTC
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent.
Regards 
https://bitcodesolution.com/

Comment 5 imrizwan.ud@gmail.com 2025-12-17 07:28:35 UTC
This vulnerability affects PeopleSoft PeopleTools versions 8.59–8.61 and can be exploited over HTTP by an unauthenticated attacker with some user interaction. If exploited, it may allow unauthorized access or modification of PeopleTools data and could impact other connected products, posing moderate confidentiality and integrity risks.
You can read more about this issue and its fix at https://startupsflow.com.

Comment 6 Jacke Mitchel 2025-12-18 04:59:23 UTC
This vulnerability affects Oracle PeopleSoft PeopleTools versions 8.59–8.61 and can be exploited over HTTP by an unauthenticated attacker with minimal user interaction. Successful exploitation may lead to unauthorized access or modification of PeopleTools data and could also impact other integrated products, resulting in moderate confidentiality and integrity risks.

Organizations using PeopleSoft are strongly advised to review this issue, apply the recommended fixes, and strengthen their security posture to prevent potential exploitation. For more insights on cybersecurity risks, vulnerabilities, and best practices, visit https://aimgrip.com


Note You need to log in before you can comment on or make changes to this bug.