Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2022-21359
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 January 2022
What is CVE-2022-21359?
This vulnerability in Oracle's PeopleSoft Enterprise PeopleTools affects supported versions 8.57, 8.58, and 8.59, allowing an unauthenticated attacker with network access via HTTP to exploit the system. While the attack requires human interaction from someone other than the attacker, the implications can be severe, leading to unauthorized modifications of the accessible data within PeopleSoft. Attackers may gain unauthorized read access, as well as the ability to update, insert, or delete data. This weakness poses a significant risk not only to the PeopleSoft product itself but may also impact related systems, requiring organizations to address the issue promptly.
Affected Version(s)
PeopleSoft Enterprise PT PeopleTools 8.57
PeopleSoft Enterprise PT PeopleTools 8.58
PeopleSoft Enterprise PT PeopleTools 8.59