Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2022-21359

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

This vulnerability in Oracle's PeopleSoft Enterprise PeopleTools affects supported versions 8.57, 8.58, and 8.59, allowing an unauthenticated attacker with network access via HTTP to exploit the system. While the attack requires human interaction from someone other than the attacker, the implications can be severe, leading to unauthorized modifications of the accessible data within PeopleSoft. Attackers may gain unauthorized read access, as well as the ability to update, insert, or delete data. This weakness poses a significant risk not only to the PeopleSoft product itself but may also impact related systems, requiring organizations to address the issue promptly.

Affected Version(s)

PeopleSoft Enterprise PT PeopleTools 8.57

PeopleSoft Enterprise PT PeopleTools 8.58

PeopleSoft Enterprise PT PeopleTools 8.59

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.