Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent.
Thanks for the update. Since this is marked as a minor change with no email notification, I suggest we document the CVE details internally and ensure related teams are aware through the security tracker to avoid missing visibility. Regards: Team https://talksocially.com/
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent. Regards Bitcodesolution
Acknowledged. Thanks for reporting. Noted that this is a minor update and no email notification will be sent. Regards https://bitcodesolution.com/
This vulnerability affects PeopleSoft PeopleTools versions 8.59–8.61 and can be exploited over HTTP by an unauthenticated attacker with some user interaction. If exploited, it may allow unauthorized access or modification of PeopleTools data and could impact other connected products, posing moderate confidentiality and integrity risks. You can read more about this issue and its fix at https://startupsflow.com.
This vulnerability affects Oracle PeopleSoft PeopleTools versions 8.59–8.61 and can be exploited over HTTP by an unauthenticated attacker with minimal user interaction. Successful exploitation may lead to unauthorized access or modification of PeopleTools data and could also impact other integrated products, resulting in moderate confidentiality and integrity risks. Organizations using PeopleSoft are strongly advised to review this issue, apply the recommended fixes, and strengthen their security posture to prevent potential exploitation. For more insights on cybersecurity risks, vulnerabilities, and best practices, visit https://aimgrip.com